VYPR

go-attestation

by Google

Source repositories

CVEs (2)

  • CVE-2026-12681HigJun 24, 2026
    risk 0.51cvss epss 0.00

    Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes before reading entries. For hashSHA256SigGUID lists, this allows attacker-controlled vendor header…

  • CVE-2022-0317MedFeb 4, 2022
    risk 0.19cvss 4.0epss 0.00

    An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-formed Quote over no/some PCRs, causing AKPublic.Verify to succeed despite the inconsistency. Subsequent use of the same set of PCR values in Eventlog.Verify…