Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-479m-364c-43vc | validateSignature Loop Variable Capture Signature Bypass in goxmldsig |
Mon, 20 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goxmldsig Project
Goxmldsig Project goxmldsig |
|
| CPEs | cpe:2.3:a:goxmldsig_project:goxmldsig:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Goxmldsig Project
Goxmldsig Project goxmldsig |
Mon, 30 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 28 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Russellhaering
Russellhaering goxmldsig |
|
| Vendors & Products |
Russellhaering
Russellhaering goxmldsig |
Thu, 26 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID. In Go versions before 1.22, or when `go.mod` uses an older version, there is a loop variable capture issue. The code takes the address of the loop variable `_ref` instead of its value. As a result, if more than one reference matches the ID or if the loop logic is incorrect, the `ref` pointer will always end up pointing to the last element in the `SignedInfo.References` slice after the loop. goxmlsig version 1.6.0 contains a patch. | |
| Title | goxmldsig has validateSignature Loop Variable Capture Signature Bypass | |
| Weaknesses | CWE-347 CWE-682 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-30T11:16:34.970Z
Reserved: 2026-03-20T16:16:48.971Z
Link: CVE-2026-33487
Updated: 2026-03-30T11:16:27.338Z
Status : Analyzed
Published: 2026-03-26T18:16:30.070
Modified: 2026-04-20T14:15:08.583
Link: CVE-2026-33487
OpenCVE Enrichment
Updated: 2026-03-27T09:25:56Z
Github GHSA