| Name | CVE-2020-29509 | 
| Description | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications. | 
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) | 
| Debian Bugs | 948190 | 
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status | 
|---|
| golang-1.15 (PTS) | bullseye | 1.15.15-1~deb11u4 | vulnerable | 
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs | 
|---|
| golang-1.11 | source | (unstable) | (unfixed) | unimportant |  |  | 
| golang-1.15 | source | (unstable) | (unfixed) | unimportant |  |  | 
| golang-1.7 | source | (unstable) | (unfixed) | unimportant |  |  | 
| golang-1.8 | source | (unstable) | (unfixed) | unimportant |  |  | 
| golang-github-russellhaering-gosaml2 | ITP |  |  |  |  | 948190 | 
Notes
Golang upstream does not consider the issue to be fixable in Go, instead
shifts responsibility to saml packages.
https://github.com/golang/go/issues/43168
https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/
https://github.com/russellhaering/gosaml2/security/advisories/GHSA-xhqq-x44f-9fgg