Lucene search

K
osvGoogleOSV:CVE-2021-33195
HistoryAug 02, 2021 - 7:15 p.m.

CVE-2021-33195

2021-08-0219:15:08
Google
osv.dev
13
go
dns lookup
vulnerability
rfc1035
software

AI Score

7.4

Confidence

Low

EPSS

0.01

Percentile

83.8%

Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.