github.com/russellhaering/gosaml2 vulnerabilities
CVEs whose affected-version data names the github.com/russellhaering/gosaml2 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2023-26483Medium· 5.3gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
▾ Sunlitrussellhaering · github.com/russellhaering/gosaml2EPSS 0.96%via OSV
CVE-2020-7711High· 7.5goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
▾ Twilightrussellhaering · github.com/russellhaering/goxmldsigEPSS 1.8%via OSV