Описание
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-1.27 | fixed | 1.27~rc3-1 | package | |
| golang-1.26 | fixed | 1.26.6-1 | package | |
| golang-1.25 | fixed | 1.25.13-1 | package | |
| golang-1.24 | removed | package | ||
| golang-1.24 | no-dsa | trixie | package | |
| golang-1.19 | removed | package | ||
| golang-1.15 | removed | package |
Примечания
https://github.com/golang/go/issues/80435
Fixed by: https://github.com/golang/go/commit/bcdba48a6adcaceabb3696e46b50be21dc739b5e (go1.27rc3)
Fixed by: https://github.com/golang/go/commit/33ecb966ca47e55034272a9146e23e9909507f6d (go1.26.6)
Fixed by: https://github.com/golang/go/commit/cafd3448c7cb0b2d793bb4144d58f72ef3f48327 (go1.25.13)
EPSS
Связанные уязвимости
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
EPSS