Web Hack List

Collected research

Coordinated disclosure of XML round-trip vulnerabilities in Go’s standard library

Documents three XML round-trip inconsistencies in Go's standard library that change a document's meaning after parsing and serialization. The mutations can alter signed SAML assertions and affected several SAML libraries, motivating token-level round-trip validation.

Record

Researcher
Juho Forsén
Published by
Mattermost
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Juho Forsén, first published at the original source. Preserved copies are kept so the citation survives its host.