Goxmldsig is a Go-language XML digital signature library used to validate cryptographic signatures in XML documents, with a narrow product scope centered on the goxmldsig implementation itself. Its vulnerability profile reflects the cryptographic-verification domain: the recurring issues center on improper signature validation, incorrect cryptographic calculations, and NULL-pointer handling in signature-processing code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Goxmldsig Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33487HIGH goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo | Mar 26, 2026 | 7.5 | 29 | NO | NO |
CVE-2020-7711HIGH This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures. | Aug 23, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-15216MEDIUM In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pas | Sep 29, 2020 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goxmldsig Project.
Media articles that mention a CVE ID that affects a product developed by Goxmldsig Project — matched by CVE ID, not by vendor name.