CVE-2020-28362
High
CVE-2020-28362
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
Exploit probability
3.8%
Published
November 18, 2020
Required by
Not available
Last source change
July 8, 2026
02 / AFFECTED SOFTWARE
Affected packages
144 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2020-28362
View original source
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
Open Source Vulnerabilities
BIT-golang-2020-28362
View original source
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
Open Source Vulnerabilities
GO-2021-0069
View original source
A number of math/big.Int methods can panic when provided large inputs due to a flawed division method.
05 / REFERENCES
Further evidence
- https://groups.google.com/g/golang-nuts/c/c-ssaaS7RMI
- https://lists.apache.org/thread.html/rd02e75766cd333a0df417588460f5e4477060633000bfe94955851fd%40%3Cissues.trafficcontrol.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2W4COUPL3YVTZ6RTEIT6LPBDJUFF3VSP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F3ZSHGNTJWCWYAKY5OLZS2XQQYHSXSUO/
- https://security.netapp.com/advisory/ntap-20201202-0004/
- https://www.arista.com/en/support/advisories-notices/security-advisories/12166-security-advisory-62
- https://nvd.nist.gov/vuln/detail/CVE-2020-28362
- https://go.dev/cl/269657
- https://go.dev/issue/42552
- https://go.googlesource.com/go/+/1e1fa5903b760c6714ba17e50bf850b01f49135c
- https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM/m/fLguyiM2CAAJ