CVE-2020-28362
Go vulnerability analysis and mitigation

Overview

CVE-2020-28362 affects Go programming language versions before 1.14.12 and 1.15.x before 1.15.4. The vulnerability was discovered and disclosed in November 2020, impacting systems using the Go programming language's math/big package. The vulnerability affects multiple software products that incorporate Go, including various NetApp products, Arista network devices, and other systems using the affected Go versions (NVD, Golang Notice).

Technical details

The vulnerability exists in the math/big package of Go's standard library and can cause a panic during recursive division of very large numbers. The vulnerability has a CVSS v3.1 Base Score of 7.5 (HIGH) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue specifically affects math/big.Int methods including Div, Exp, DivMod, Quo, Rem, QuoRem, Mod, ModInverse, ModSqrt, Jacobi, and GCD when provided with crafted large inputs (Golang Notice, Arista Advisory).

Impact

When successfully exploited, this vulnerability can lead to a Denial of Service (DoS) condition. The vulnerability affects applications that use the math/big package via TLS connections or client certificate authentication. In network devices and applications, this can result in agent crashes, service disruptions, and impact overall product functionality (NetApp Advisory, Arista Advisory).

Mitigation and workarounds

The primary mitigation is to upgrade to Go version 1.14.12 or 1.15.5 or later. For network devices and applications, it is recommended to restrict TLS connections to trusted sources using Control-Plane ACLs or iptables rules. As a security best practice, TLS connections should only be accepted from trusted sources (Arista Advisory, NetApp Advisory).

Community reactions

Multiple vendors including NetApp, Arista, and Red Hat released security advisories and patches for their affected products. The vulnerability was initially reported by the Go Ethereum team and the OSS-Fuzz project, leading to a coordinated response from the Go development team (Golang Notice).

Additional resources


SourceThis report was generated using AI

Related Go vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-54365HIGH8.7
  • Go logoGo
  • kubeflow-katib
NoYesJun 23, 2026
CVE-2026-39822HIGH7.8
  • Go logoGo
  • influx
NoYesJul 08, 2026
CVE-2026-42504HIGH7.5
  • Go logoGo
  • kube-conformance-1.35
NoYesJun 02, 2026
CVE-2026-42505MEDIUM5.3
  • Go logoGo
  • net-kourier-1.22
NoYesJul 08, 2026
CVE-2026-42507MEDIUM5.3
  • Go logoGo
  • longhorn-manager-fips-1.11
NoYesJun 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management