logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2021-33195

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2021-33195

Description:
Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.
Last updated date:
09/14/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
09/02/2021
Reference url to background

https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy