blob: 70a3b52e41512d6f6a7aa48ce259937fef0d58c0 [file] [edit]
id: GO-2026-4753
modules:
- module: github.com/russellhaering/goxmldsig
versions:
- fixed: 1.6.0
vulnerable_at: 1.5.0
summary: |-
Loop Variable Capture Signature Bypass in goxmldsig in
github.com/russellhaering/goxmldsig
cves:
- CVE-2026-33487
ghsas:
- GHSA-479m-364c-43vc
references:
- advisory: https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-479m-364c-43vc
notes:
- failed to auto-populate symbols: no commits found for github.com/russellhaering/goxmldsig
source:
id: GHSA-479m-364c-43vc
created: 2026-03-26T15:43:22.433310227-04:00
review_status: REVIEWED