
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-27918 affects the encoding/xml package in Go versions before 1.15.9 and 1.16.x before 1.16.1. The vulnerability was discovered and disclosed on March 10, 2021, and affects the Go programming language's XML processing functionality (CVE, Go Announce).
The vulnerability manifests as an infinite loop condition in the encoding/xml package when using xml.NewTokenDecoder with a custom TokenReader. The issue occurs specifically when the TokenReader returns EOF (End of File) in the middle of an element. This vulnerability can be triggered through the Decode, DecodeElement, or Skip methods of the XML decoder (Go Announce). The vulnerability has been assigned a CVSS v3 score of 7.5 (High) (Ubuntu).
The vulnerability can lead to a denial of service condition through resource exhaustion caused by the infinite loop. The CVSS scoring indicates high impact on availability while maintaining unchanged scope, with no impact on confidentiality or integrity (Ubuntu).
The vulnerability is exploitable remotely and requires no privileges or user interaction. It has a low attack complexity, making it relatively straightforward to exploit (Ubuntu).
The vulnerability has been fixed in Go versions 1.15.9 and 1.16.1. Users are recommended to upgrade to these versions or later to address the security issue. For users of Red Hat Enterprise Linux, security updates have been provided through the go-toolset:rhel8 module (Red Hat).
The vulnerability was reported by Sam Whited and was addressed promptly by the Go team through a security release announcement. The Go team recommended all users to update to either Go 1.16.1 or Go 1.15.9, with a preference for Go 1.16.1 if users were unsure which version to choose (Go Announce).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."