VYPR

go-attestation

by Google

Source repositories

CVEs (3)

  • CVE-2026-12681HigJun 24, 2026
    risk 0.51cvss epss 0.00

    Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes before reading entries. For hashSHA256SigGUID lists, this allows attacker-controlled vendor header…

  • CVE-2026-19201MedSep 9, 2026
    risk 0.36cvss epss 0.00

    An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation function recurses for every nested elamAggregation…

  • CVE-2022-0317MedFeb 4, 2022
    risk 0.19cvss 4.0epss 0.00

    An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-formed Quote over no/some PCRs, causing AKPublic.Verify to succeed despite the inconsistency. Subsequent use of the same set of PCR values in Eventlog.Verify…