xmlquery lacks check for whether LoadURL response is in XML format, causing denial of service
High severity
GitHub Reviewed
Published
Oct 7, 2022
to the GitHub Advisory Database
•
Updated Jan 22, 2025
Description
Published by the National Vulnerability Database
Sep 16, 2020
Published to the GitHub Advisory Database
Oct 7, 2022
Reviewed
Oct 7, 2022
Last updated
Jan 22, 2025
xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impact.
References