encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-03-10T23:54:43

Updated: 2024-08-03T21:33:16.406Z

Reserved: 2021-03-03T00:00:00

Link: CVE-2021-27918

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-03-11T00:15:12.030

Modified: 2022-12-13T16:28:13.860

Link: CVE-2021-27918

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-03-10T00:00:00Z

Links: CVE-2021-27918 - Bugzilla