GHSA-p6mv-vmpw-j23r
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 18, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.