Skip to content

Conversation

Fidget-Grep
Copy link

Updates

  • Affected products
  • References
  • Source code location

Comments
As per the Go Vulnerability Database (https://pkg.go.dev/vuln/GO-2021-0142) this vulnerability also affects the Go Standard Library encoding/binary. I've added this library as an affected package and listed the appropriate affected versions as per the advisory. I also added some helpful reference links and a missing source code link to the "xz" project.
Let me know if any information is missing or incorrect, thanks.

@github-actions github-actions bot changed the base branch from main to Fidget-Grep/advisory-improvement-6316 October 13, 2025 18:18
@Fidget-Grep
Copy link
Author

Actually, reading further and I think this advisory shouldn't actually mention "github.com/ulikunitz/xz". The infinite loop vuln mentioned here is already covered by this GHSA: GHSA-25xm-hr59-7c27. It looks like this GHSA is actually about the infinite read loop in encoding/binary. I'll see if I can update the PR.

@helixplant
Copy link

Hi @Fidget-Grep,
Thank you for bringing this to our attention! CVE-2020-16845 does pertain to Go and specifically mentions the encoding/binary standard library package. However, at this time we are unable to issue alerts for Go standard library packages, so this advisory will be withdrawn to prevent any confusion.

@advisory-database advisory-database bot merged commit 2b29c03 into Fidget-Grep/advisory-improvement-6316 Oct 14, 2025
3 checks passed
@advisory-database
Copy link
Contributor

Hi @Fidget-Grep! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the Fidget-Grep-GHSA-q6gq-997w-f55g branch October 14, 2025 19:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants