github.com/russellhaering/goxmldsig
Pure Go implementation of XML Digital Signatures
Activity
- Latest release
- 1mo ago
- Total releases
- 8
- Cadence
- ~11 months
- Last 12 months
- 2
Reach
- Stars
- 178
Details
- First release
- Sep 29, 2020
| Version | Released | |
|---|---|---|
v1.6.1
patch
|
v1.6.1
patch
Dependencies (3)
|
|
v1.6.0
minor
|
v1.6.0
minor
Dependencies (3)
|
|
v1.5.0
minor
1 CVE
CVE-2026-33487
GO-2026-4753
GHSA-479m-364c-43vc
Mar 27, 2026
Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Fixed in
1.6.0
Updated Mar 30, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (3)
|
|
v1.4.0
minor
1 CVE
CVE-2026-33487
GO-2026-4753
GHSA-479m-364c-43vc
Mar 27, 2026
Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Fixed in
1.6.0
Updated Mar 30, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (3)
|
|
v1.3.0
minor
1 CVE
CVE-2026-33487
GO-2026-4753
GHSA-479m-364c-43vc
Mar 27, 2026
Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Fixed in
1.6.0
Updated Mar 30, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (3)
|
|
v1.2.0
minor
1 CVE
CVE-2026-33487
GO-2026-4753
GHSA-479m-364c-43vc
Mar 27, 2026
Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Fixed in
1.6.0
Updated Mar 30, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (3)
|
|
v1.1.1
patch
1 CVE
CVE-2026-33487
GO-2026-4753
GHSA-479m-364c-43vc
Mar 27, 2026
Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Fixed in
1.6.0
Updated Mar 30, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (3)
|
|
v1.1.0
initial
2 CVEs
CVE-2026-33487
GO-2026-4753
GHSA-479m-364c-43vc
Mar 27, 2026
Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Loop Variable Capture Signature Bypass in goxmldsig in github.com/russellhaering/goxmldsig Fixed in
1.6.0
Updated Mar 30, 2026 · Source: OSV.dev
CVE-2020-7711
GHSA-prjq-f4q3-fvfr
CVE-2020-7731
GHSA-gq5r-cc4w-g8xf
GHSA-mqqv-chpx-vq25
GO-2020-0046
SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOSAML2-608302
Nov 15, 2022
github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactIn versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference. PatchesThe issue was patched in v0.7.0, released on March 2, 2022. WorkaroundsCallers to ReferencesSee issue #59 for details. Fixed in
1.1.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
v1.1.0
initial
Dependencies (3)
|