Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2021-27918
Go vulnerability analysis and mitigation

Overview

CVE-2021-27918 affects the encoding/xml package in Go versions before 1.15.9 and 1.16.x before 1.16.1. The vulnerability was discovered and disclosed on March 10, 2021, and affects the Go programming language's XML processing functionality (CVE, Go Announce).

Technical details

The vulnerability manifests as an infinite loop condition in the encoding/xml package when using xml.NewTokenDecoder with a custom TokenReader. The issue occurs specifically when the TokenReader returns EOF (End of File) in the middle of an element. This vulnerability can be triggered through the Decode, DecodeElement, or Skip methods of the XML decoder (Go Announce). The vulnerability has been assigned a CVSS v3 score of 7.5 (High) (Ubuntu).

Impact

The vulnerability can lead to a denial of service condition through resource exhaustion caused by the infinite loop. The CVSS scoring indicates high impact on availability while maintaining unchanged scope, with no impact on confidentiality or integrity (Ubuntu).

Exploitability

The vulnerability is exploitable remotely and requires no privileges or user interaction. It has a low attack complexity, making it relatively straightforward to exploit (Ubuntu).

Mitigation and workarounds

The vulnerability has been fixed in Go versions 1.15.9 and 1.16.1. Users are recommended to upgrade to these versions or later to address the security issue. For users of Red Hat Enterprise Linux, security updates have been provided through the go-toolset:rhel8 module (Red Hat).

Community reactions

The vulnerability was reported by Sam Whited and was addressed promptly by the Go team through a security release announcement. The Go team recommended all users to update to either Go 1.16.1 or Go 1.15.9, with a preference for Go 1.16.1 if users were unsure which version to choose (Go Announce).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Alpine

Fixed

edge

go: 1.16.2-r0

Fixed

v3.18

go: 1.16.2-r0

Fixed

v3.19

go: 1.16.2-r0

Fixed

v3.20

go: 1.16.2-r0

Fixed

v3.21

go: 1.16.2-r0

Fixed

v3.22

go: 1.16.2-r0

Fixed

v3.23

go: 1.16.2-r0

Fixed

Arch Linux

Fixed

rolling

go: 2:1.16.1-1

Fixed

SourceThis report was generated using AI

Related Go vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56865HIGH8.4
  • Go logoGo
  • volume-modifier-for-k8s-fips
NoYesAug 13, 2026
CVE-2026-56864HIGH7.5
  • Go logoGo
  • http-echo
NoYesAug 13, 2026
CVE-2026-56862HIGH7.5
  • Go logoGo
  • kube-state-metrics-2.6
NoYesAug 13, 2026
CVE-2026-56859HIGH7.5
  • Go logoGo
  • fluxcd-helm-controller-fips
NoYesAug 13, 2026
CVE-2026-56860MEDIUM5.9
  • Go logoGo
  • vcluster-fips
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management