CVE-2020-29511 PUBLISHED

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

EPSS 0.19% · 40.4th percentile

Risk Scores

EPSS Score
0.19%
40.4th percentile

Affected Products

VendorProductVersions
Cloudflarestream
Bitnamigolang0
Bitnamigolang0

Timeline

References

Open in Interactive Console →