Russellhaering Goxmldsig vulnerabilities
2 known vulnerabilities affecting russellhaering/goxmldsig.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-33487HIGHCVSS 7.5fixed in 1.6.02026-03-26
CVE-2026-33487 [HIGH] CWE-347 CVE-2026-33487: goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSig
goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID. In Go versions before 1.22, or when `go.mod` uses an older version, there is a loop variable capture issue. The cod
cvelistv5nvd
CVE-2020-15216MEDIUMCVSS 6.5fixed in 1.1.02020-09-29
CVE-2020-15216 [MEDIUM] CWE-347 CVE-2020-15216: In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version
cvelistv5nvd