CVE-2026-33487Disclosure(goxmldsig_project / goxmldsig)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID. In Go versions before 1.22, or when `go.mod` uses an older version, there is a loop variable capture issue. The code takes the address of the loop variable `_ref` instead of its value. As a result, if more than one reference matches the ID or if the loop logic is incorrect, the `ref` pointer will always end up pointing to the last element in the `SignedInfo.References` slice after the loop. goxmlsig version 1.6.0 contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347CWE-682

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • goxmldsig

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
goxmldsig

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-26: 2Mentions · 2026-03-29: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-29: 103-2603-29
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-262
Disclosure2
2026-03-291
Disclosure1
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A signature bypass (CVE-2026-33487) affects the `goxmldsig` library. This flaw allows crafted XML digital signatures to be validated incorrectly. Evaluate usage and anticipate official fixes. #GoLang #XMLSecurity #InfoSec https://www.pulsepatch.io/posts/cve-2026-33487-goxmldsig-signature-bypass

    Post summary

    The post highlights a signature bypass vulnerability in the goxmldsig library that lets crafted XML signatures be incorrectly validated, with no known PoC or exploitation evidence, but notes that official fixes are expected soon.

    0000040
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33487 goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in t… https://www.cve.org/CVERecord?id=CVE-2026-33487 ----- Traducción: CVE-2026-33487 gox… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑33487, a vulnerability in the goxmlsig library affecting the validateSignature function before v1.6.0; no PoC, exploit code, patch, or active exploitation is mentioned.

    0000027
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33487 goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in t… https://www.cve.org/CVERecord?id=CVE-2026-33487

    Post summary

    The text announces CVE-2026-33487 in the goxmlsig library, noting that prior to version 1.6.0 the validateSignature function processes references in a way that triggers the vulnerability.

    00000195
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgoxmldsig_projectgoxmldsig---

Explore more