moov-io/signedxml

moov-io/signedxml

Releases10
Frequency3 months 4 weeks
Last Release
Stars66
pure go library for processing signed XML documents

CVE History

CVEPublishedCVSS v3CVSS v2
9.1 CRITICAL

In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW).