CVE-2020-7919: Debian Linux
High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 31 only
- Golang Go: from 1.12, before 1.12.6 (fixed in 1.12.6); from 1.13, before 1.13.7 (fixed in 1.13.7)
- Netapp Cloud Insights Telegraf: affected versions not specified
Published 2020-03-16. Last modified 2026-06-17.