[CVE-2020-16250] Unexpected security footguns in Go's parsers
blog.trailofbits.com | blog | CVE-2020-16250 | #authentication-bypass | #deserialization | #go | #json | #xml | #yaml | #parsers | #cve-2020-16250
Summary
Unexpected behaviors in Go's JSON, XML, and YAML parsers let attackers bypass authentication, evade authorization, and exfiltrate data—seen in HashiCorp Vault's CVE-2020-16250 and real engagements.
- Published
- Collected
Skip to content