CVE-2020-7919: Debian Linux

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 31 only
  • Golang Go: from 1.12, before 1.12.6 (fixed in 1.12.6); from 1.13, before 1.13.7 (fixed in 1.13.7)
  • Netapp Cloud Insights Telegraf: affected versions not specified

Published 2020-03-16. Last modified 2026-06-17.