blob: f194a4ae2f61d4580ee49445368974d75a470df7 [file] [log] [blame]
module: github.com/antchfx/xmlquery
versions:
- fixed: v1.3.1
description: |
LoadURL does not check the Content-Type of loaded resources,
which can cause a panic due to nil pointer deference if the loaded
resource is not XML. If user supplied URLs are loaded, this may be
used as a denial of service vector.
published: 2021-04-14T20:04:52Z
cves:
- CVE-2020-25614
credit: '@dwisiswant0'
symbols:
- LoadURL
links:
commit: https://github.com/antchfx/xmlquery/commit/5648b2f39e8d5d3fc903c45a4f1274829df71821
context:
- https://github.com/antchfx/xmlquery/issues/39