Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2020-16250] Unexpected security footguns in Go's parsers

Summary

Unexpected behaviors in Go's JSON, XML, and YAML parsers let attackers bypass authentication, evade authorization, and exfiltrate data—seen in HashiCorp Vault's CVE-2020-16250 and real engagements.
Published
Collected

original ↗

Related coverage

back