CVE-2021-27918

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.09 % (41th)
0.09% Progress
Affected Products 1
Advisories 15

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.

Weaknesses
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2021-03-11 00:15:12
(3 years ago)
Updated Date
2022-12-13 16:28:13
(21 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Golang Go prior 1.15.9 version cpe:2.3:a:golang:go < 1.15.9
  Golang Go from 1.16.0 version and prior 1.16.1 version cpe:2.3:a:golang:go >= 1.16.0 < 1.16.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...