russellhaering has 3 CVEs on record between 2021 and 2023. The median CVSS is 5.3 (medium). Most affected products: github.com/russellhaering/goxmldsig (2), github.com/russellhaering/gosaml2 (1).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- github.com/russellhaering/goxmldsig 2
- github.com/russellhaering/gosaml2 1
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2020-7711High· 7.5goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures42CVE-2023-26483Medium· 5.3gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb29CVE-2020-15216Medium· 5.3github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass29
russellhaering vulnerabilities
CVEs affecting russellhaering, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2023-26483Medium· 5.3gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
▾ Sunlitrussellhaering · github.com/russellhaering/gosaml2EPSS 0.96%via OSV
CVE-2020-7711High· 7.5goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures
▾ Twilightrussellhaering · github.com/russellhaering/goxmldsigEPSS 1.8%via OSV
CVE-2020-15216Medium· 5.3github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
▾ Sunlitrussellhaering · github.com/russellhaering/goxmldsigEPSS 0.90%via OSV