Headline
GHSA-5rhg-xhgr-5hfj: go-saml's XML Digital Signatures use SHA-1
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.
go-saml’s XML Digital Signatures use SHA-1
Moderate severity GitHub Reviewed Published Dec 28, 2022 • Updated Dec 30, 2022
Related news
CVE-2020-36563: GO-2020-0047 - Go Packages
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.