GHSA-93m7-c69f-5cfj
Dashboard / Vulnerabilities / GHSA-93m7-c69f-5cfj
GHSA-93m7-c69f-5cfj
Summary: xmlquery lacks check for whether LoadURL response is in XML format, causing denial of service
Details: xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impact.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-25614, https://github.com/antchfx/xmlquery/issues/39, https://github.com/antchfx/xmlquery/commit/5648b2f39e8d5d3fc903c45a4f1274829df71821, https://github.com/antchfx/xmlquery, https://github.com/antchfx/xmlquery/compare/v1.3.0...v1.3.1, https://pkg.go.dev/vuln/GO-2020-0048
Affected packages
Package
Name: github.com/antchfx/xmlquery
Purl: pkg:golang/github.com/antchfx/xmlquery
Affected ranges
Type: SEMVER
Events:
