Google Go-Attestation vulnerabilities
3 known vulnerabilities affecting google/go-attestation.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-12681P3HIGHCVSS 8.9≤ 0.6.02026-06-24
CVE-2026-12681 [HIGH] CWE-1285 CVE-2026-12681: Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-atte
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes before reading entries. For hashSHA256SigGUID lists, this allows attacker-controlled vendor header bytes to be appended to the trusted SHA256 hash list. A crafted TPM event
nvd
CVE-2026-19201P3MEDIUMCVSS 6.6≥ 0.0.0, ≤ 0.6.12026-09-09
CVE-2026-19201 [MEDIUM] CWE-674 CVE-2026-19201: An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestatio
An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation function recurses for every nested elamAggregation sub-event without enforcing a maximum recursion depth limit, while the
nvd
CVE-2022-0317P4LOWCVSS 3.3fixed in 0.3.32022-02-04
CVE-2022-0317 [LOW] CWE-20 CVE-2022-0317: An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to prov
An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-formed Quote over no/some PCRs, causing AKPublic.Verify to succeed despite the inconsistency. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacke
nvd