CVE-2022-28131

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.19 % (56th)
0.19% Progress
Affected Products 3
Advisories 49

Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

Weaknesses
CWE-674
Uncontrolled Recursion
CVE Status
PUBLISHED
CNA
Go Project
Published Date
2022-08-10 20:15:32
(2 years ago)
Updated Date
2023-11-07 03:45:33
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Golang Go prior 1.17.12 version cpe:2.3:a:golang:go < 1.17.12
  Golang Go from 1.18.0 version and prior 1.18.4 version cpe:2.3:a:golang:go >= 1.18.0 < 1.18.4

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 35 cpe:2.3:o:fedoraproject:fedora:35

Configuration #3

    CPE23 From Up To
  Netapp Cloud Insights Telegraf cpe:2.3:a:netapp:cloud_insights_telegraf:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...