This affects all versions of package github.com/russellhaering/goxmldsig prior to 1.1.1. There is a crash on nil-pointer dereference caused by sending malformed XML signatures. This issue is patched in version 1.1.1.
{
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-476"
],
"nvd_published_at": null,
"github_reviewed_at": "2022-10-07T07:17:56Z"
}