« Volver al listado

Goxmldsig Project

Goxmldsig Project Goxmldsig: vulnerabilidades y CVE

Goxmldsig Project Goxmldsig tiene 3 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE3
Últimos 12 meses1
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-33487Alta (7.5)0.42%—26 mar 2026
goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the…
CVE-2020-15216Media (6.5)0.90%—29 sept 2020
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one.…
CVE-2020-7711Alta (7.5)1.8%—23 ago 2020
This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application1
  2. T1553.002 Code Signing1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.