Lucene search

K
osvGoogleOSV:CVE-2021-27918
HistoryMar 11, 2021 - 12:15 a.m.

CVE-2021-27918

2021-03-1100:15:12
Google
osv.dev
5

6.6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

40.3%

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.