golang go CVE-2021-29923 vulnerability in GoLang and Other Products
Published on August 7, 2021

product logo product logo product logo
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.

Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2021-29923

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2021-29923 are published in these products:

 
 
 

Exploit Probability

EPSS
0.12%
Percentile
30.09%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.