CVE-2020-36563: Robotsandpencils Go-SAML

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.

Affected products

Published 2022-12-28. Last modified 2026-06-17.