github.com/russellhaering/goxmldsig vulnerabilities
CVEs whose affected-version data names the github.com/russellhaering/goxmldsig package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2020-7711High· 7.5goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
▾ Twilightrussellhaering · github.com/russellhaering/goxmldsigEPSS 1.8%via OSV
CVE-2020-15216Medium· 5.3github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
▾ Sunlitrussellhaering · github.com/russellhaering/goxmldsigEPSS 0.90%via OSV