GHSA-g7v2-7v9m-q9j4
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 18, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.