[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2020-16845":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":19,"aliases":20,"duplicate_of":9,"upstream":24,"downstream":25,"duplicates":92,"related":93,"reserved_at":9,"published_at":102,"modified_at":103,"state":104,"summary":105,"references_raw":114,"kevs":246,"epss":247,"epss_history":250,"metrics":513,"affected":525},"CVE-2020-16845","Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-835","Loop with Unreachable Exit Condition ('Infinite Loop')","The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.","weakness","Incomplete","Base",[],[],[21,22,23],"GHSA-q6gq-997w-f55g","BIT-golang-2020-16845","GO-2021-0142",[],[26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72,74,76,78,80,82,84,86,88,90],{"_key":27},"OPENSUSE-SU-2020:1178-1",{"_key":29},"SUSE-SU-2020:2562-1",{"_key":31},"OPENSUSE-SU-2020:1194-1",{"_key":33},"OPENSUSE-SU-2020:1405-1",{"_key":35},"OPENSUSE-SU-2020:1407-1",{"_key":37},"OPENSUSE-SU-2024:10806-1",{"_key":39},"OPENSUSE-SU-2024:10807-1",{"_key":41},"DLA-2459-1",{"_key":43},"DLA-2460-1",{"_key":45},"DSA-4848-1",{"_key":47},"RHBA-2020:4197",{"_key":49},"RHBA-2020:4229",{"_key":51},"RHBA-2020:5123",{"_key":53},"RHBA-2020:5356",{"_key":55},"RHSA-2020:5119",{"_key":57},"RHSA-2020:5159",{"_key":59},"RHSA-2020:5649",{"_key":61},"RHSA-2021:0713",{"_key":63},"RHSA-2021:1016",{"_key":65},"RHSA-2021:2122",{"_key":67},"RHSA-2021:4103",{"_key":69},"MGASA-2020-0325",{"_key":71},"USN-5725-1",{"_key":73},"DEBIAN-CVE-2020-16845",{"_key":75},"RHSA-2021:0172",{"_key":77},"RHSA-2021:0956",{"_key":79},"RHSA-2021:1366",{"_key":81},"UBUNTU-CVE-2020-16845",{"_key":83},"USN-5725-2",{"_key":85},"RHSA-2020:3665",{"_key":87},"RHSA-2020:4214",{"_key":89},"RHSA-2020:4297",{"_key":91},"RHSA-2020:5606",[],[94,95,96,97,98,99,100,101],{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":69},"2020-08-06T17:03:33.000Z","2024-08-04T13:45:33.920Z","Modified",{"cisa_kev":106,"cisa_ransomware":106,"cisa_vendor":9,"epss_severity":107,"epss_score":108,"severity":109,"severity_score":110,"severity_version":111,"severity_source":112,"severity_vector":113,"severity_status":104},false,"low",0.00147,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",[115,121,131,135,140,144,148,152,156,160,165,169,174,178,183,187,192,196,200,204,208,212,216,220,224,228,233,237,242],{"url":116,"sources":117,"tags":119},"https://groups.google.com/forum/#%21topic/golang-announce/_ulYYcIWg3Q",[118,112],"cve.org",[120],"X Refsource MISC",{"url":122,"sources":123,"tags":125},"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00021.html",[118,112,124],"osv_go",[126,127,128,129,130],"Vendor Advisory","X Refsource SUSE","Mailing List","Third Party Advisory","WEB",{"url":132,"sources":133,"tags":134},"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00028.html",[118,112,124],[126,127,128,129,130],{"url":136,"sources":137,"tags":138},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RCFJTMKHY5ICGEM5BUFUEDDGSPJ25XU/",[118,112],[126,139],"X Refsource FEDORA",{"url":141,"sources":142,"tags":143},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWRBAH4UZJO3RROQ72SYCUPFCJFA22FO/",[118,112],[126,139],{"url":145,"sources":146,"tags":147},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TACQFZDPA7AUR6TRZBCX2RGRFSDYLI7O/",[118,112],[126,139],{"url":149,"sources":150,"tags":151},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WV2VWKFTH4EJGZBZALVUJQJOAQB5MDQ4/",[118,112],[126,139],{"url":153,"sources":154,"tags":155},"http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00029.html",[118,112,124],[126,127,128,129,130],{"url":157,"sources":158,"tags":159},"http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00030.html",[118,112,124],[126,127,128,129,130],{"url":161,"sources":162,"tags":163},"https://lists.debian.org/debian-lts-announce/2020/11/msg00037.html",[118,112,124],[128,164,129,130],"X Refsource MLIST",{"url":166,"sources":167,"tags":168},"https://lists.debian.org/debian-lts-announce/2020/11/msg00038.html",[118,112,124],[128,164,129,130],{"url":170,"sources":171,"tags":172},"https://www.debian.org/security/2021/dsa-4848",[118,112,124],[126,173,129,130],"X Refsource DEBIAN",{"url":175,"sources":176,"tags":177},"https://www.oracle.com/security-alerts/cpuApr2021.html",[118,112,124],[120,129,130],{"url":179,"sources":180,"tags":181},"https://groups.google.com/forum/#%21topic/golang-announce/NyPIaucMgXo",[118,112],[182],"X Refsource CONFIRM",{"url":184,"sources":185,"tags":186},"https://security.netapp.com/advisory/ntap-20200924-0002/",[118,112],[182,129],{"url":188,"sources":189,"tags":190},"https://nvd.nist.gov/vuln/detail/CVE-2020-16845",[124],[191],"Advisory",{"url":193,"sources":194,"tags":195},"https://github.com/ulikunitz/xz/issues/35",[124],[130],{"url":197,"sources":198,"tags":199},"https://github.com/ulikunitz/xz/commit/69c6093c7b2397b923acf82cb378f55ab2652b9b",[124],[130],{"url":201,"sources":202,"tags":203},"https://groups.google.com/forum/#!topic/golang-announce/NyPIaucMgXo",[124],[130],{"url":205,"sources":206,"tags":207},"https://groups.google.com/forum/#!topic/golang-announce/_ulYYcIWg3Q",[124],[130],{"url":209,"sources":210,"tags":211},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6RCFJTMKHY5ICGEM5BUFUEDDGSPJ25XU",[124],[130],{"url":213,"sources":214,"tags":215},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KWRBAH4UZJO3RROQ72SYCUPFCJFA22FO",[124],[130],{"url":217,"sources":218,"tags":219},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TACQFZDPA7AUR6TRZBCX2RGRFSDYLI7O",[124],[130],{"url":221,"sources":222,"tags":223},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WV2VWKFTH4EJGZBZALVUJQJOAQB5MDQ4",[124],[130],{"url":225,"sources":226,"tags":227},"https://security.netapp.com/advisory/ntap-20200924-0002",[124],[130],{"url":229,"sources":230,"tags":231},"https://go.dev/cl/247120",[124],[232],"FIX",{"url":234,"sources":235,"tags":236},"https://go.googlesource.com/go/+/027d7241ce050d197e7fabea3d541ffbe3487258",[124],[232],{"url":238,"sources":239,"tags":240},"https://go.dev/issue/40618",[124],[241],"REPORT",{"url":243,"sources":244,"tags":245},"https://groups.google.com/g/golang-announce/c/NyPIaucMgXo",[124],[130],[],{"date":248,"score":108,"percentile":249},"2026-06-04",0.34885,[251,255,258,261,263,266,269,272,275,278,280,283,286,289,292,296,299,302,305,308,311,314,317,320,323,326,329,332,335,338,341,344,347,349,352,355,358,361,364,367,370,373,376,379,382,385,388,391,394,396,399,401,404,407,410,413,416,419,422,425,428,431,434,437,439,442,445,448,451,454,456,459,462,464,466,468,471,474,477,480,483,486,489,492,495,498,501,504,507,510],{"date":252,"score":253,"percentile":254},"2025-11-04",0.00084,0.25265,{"date":256,"score":253,"percentile":257},"2025-11-05",0.25246,{"date":259,"score":253,"percentile":260},"2025-11-06",0.25252,{"date":262,"score":253,"percentile":260},"2025-11-07",{"date":264,"score":253,"percentile":265},"2025-11-08",0.25253,{"date":267,"score":253,"percentile":268},"2025-11-09",0.25212,{"date":270,"score":253,"percentile":271},"2025-11-10",0.25174,{"date":273,"score":253,"percentile":274},"2025-11-11",0.25177,{"date":276,"score":253,"percentile":277},"2025-11-12",0.25204,{"date":279,"score":253,"percentile":277},"2025-11-13",{"date":281,"score":253,"percentile":282},"2025-11-14",0.25199,{"date":284,"score":253,"percentile":285},"2025-11-15",0.25188,{"date":287,"score":253,"percentile":288},"2025-11-16",0.2514,{"date":290,"score":253,"percentile":291},"2025-11-17",0.25098,{"date":293,"score":294,"percentile":295},"2025-11-18",0.03739,0.86838,{"date":297,"score":294,"percentile":298},"2025-11-19",0.86839,{"date":300,"score":294,"percentile":301},"2025-11-20",0.86841,{"date":303,"score":253,"percentile":304},"2025-11-21",0.2502,{"date":306,"score":253,"percentile":307},"2025-11-22",0.25016,{"date":309,"score":253,"percentile":310},"2025-11-23",0.24965,{"date":312,"score":253,"percentile":313},"2025-11-24",0.24939,{"date":315,"score":253,"percentile":316},"2025-11-25",0.24923,{"date":318,"score":253,"percentile":319},"2025-11-26",0.24911,{"date":321,"score":253,"percentile":322},"2025-11-27",0.24909,{"date":324,"score":253,"percentile":325},"2025-11-28",0.24883,{"date":327,"score":253,"percentile":328},"2025-11-29",0.24874,{"date":330,"score":253,"percentile":331},"2025-11-30",0.24847,{"date":333,"score":253,"percentile":334},"2025-12-01",0.24887,{"date":336,"score":253,"percentile":337},"2025-12-02",0.24912,{"date":339,"score":253,"percentile":340},"2025-12-03",0.24922,{"date":342,"score":253,"percentile":343},"2025-12-04",0.24853,{"date":345,"score":253,"percentile":346},"2025-12-05",0.24905,{"date":348,"score":253,"percentile":346},"2025-12-06",{"date":350,"score":253,"percentile":351},"2025-12-07",0.24872,{"date":353,"score":253,"percentile":354},"2025-12-08",0.24878,{"date":356,"score":253,"percentile":357},"2025-12-09",0.24932,{"date":359,"score":253,"percentile":360},"2025-12-10",0.24999,{"date":362,"score":253,"percentile":363},"2025-12-11",0.25012,{"date":365,"score":253,"percentile":366},"2025-12-12",0.25025,{"date":368,"score":253,"percentile":369},"2025-12-13",0.25027,{"date":371,"score":253,"percentile":372},"2025-12-14",0.25001,{"date":374,"score":253,"percentile":375},"2025-12-15",0.24974,{"date":377,"score":253,"percentile":378},"2025-12-16",0.24992,{"date":380,"score":253,"percentile":381},"2025-12-17",0.25067,{"date":383,"score":253,"percentile":384},"2025-12-18",0.25127,{"date":386,"score":253,"percentile":387},"2025-12-19",0.25142,{"date":389,"score":253,"percentile":390},"2025-12-20",0.25112,{"date":392,"score":253,"percentile":393},"2025-12-21",0.25061,{"date":395,"score":253,"percentile":307},"2025-12-22",{"date":397,"score":253,"percentile":398},"2025-12-23",0.24993,{"date":400,"score":253,"percentile":372},"2025-12-24",{"date":402,"score":253,"percentile":403},"2025-12-25",0.25077,{"date":405,"score":253,"percentile":406},"2025-12-26",0.25064,{"date":408,"score":253,"percentile":409},"2025-12-27",0.25062,{"date":411,"score":253,"percentile":412},"2025-12-28",0.24931,{"date":414,"score":253,"percentile":415},"2025-12-29",0.24899,{"date":417,"score":253,"percentile":418},"2025-12-30",0.24896,{"date":420,"score":253,"percentile":421},"2025-12-31",0.24957,{"date":423,"score":253,"percentile":424},"2026-01-01",0.25055,{"date":426,"score":253,"percentile":427},"2026-01-02",0.25047,{"date":429,"score":253,"percentile":430},"2026-01-03",0.2503,{"date":432,"score":253,"percentile":433},"2026-01-04",0.24934,{"date":435,"score":253,"percentile":436},"2026-01-05",0.24914,{"date":438,"score":253,"percentile":340},"2026-01-06",{"date":440,"score":253,"percentile":441},"2026-01-07",0.2495,{"date":443,"score":253,"percentile":444},"2026-01-08",0.24996,{"date":446,"score":253,"percentile":447},"2026-01-09",0.24973,{"date":449,"score":253,"percentile":450},"2026-01-10",0.24944,{"date":452,"score":253,"percentile":453},"2026-01-11",0.2492,{"date":455,"score":253,"percentile":325},"2026-01-12",{"date":457,"score":253,"percentile":458},"2026-01-13",0.24859,{"date":460,"score":253,"percentile":461},"2026-01-14",0.24917,{"date":463,"score":253,"percentile":322},"2026-01-15",{"date":465,"score":253,"percentile":313},"2026-01-16",{"date":467,"score":253,"percentile":450},"2026-01-17",{"date":469,"score":253,"percentile":470},"2026-01-18",0.24921,{"date":472,"score":253,"percentile":473},"2026-01-19",0.24875,{"date":475,"score":253,"percentile":476},"2026-01-20",0.24858,{"date":478,"score":253,"percentile":479},"2026-01-21",0.24814,{"date":481,"score":253,"percentile":482},"2026-01-22",0.24801,{"date":484,"score":253,"percentile":485},"2026-01-23",0.24884,{"date":487,"score":253,"percentile":488},"2026-01-24",0.2489,{"date":490,"score":253,"percentile":491},"2026-01-25",0.24805,{"date":493,"score":253,"percentile":494},"2026-01-26",0.24712,{"date":496,"score":253,"percentile":497},"2026-01-27",0.24701,{"date":499,"score":253,"percentile":500},"2026-01-28",0.24699,{"date":502,"score":253,"percentile":503},"2026-01-29",0.24661,{"date":505,"score":253,"percentile":506},"2026-01-30",0.24646,{"date":508,"score":253,"percentile":509},"2026-01-31",0.2464,{"date":511,"score":253,"percentile":512},"2026-02-01",0.24688,[514,523],{"source":112,"cvss_v2_0":515,"cvss_v3_0":9,"cvss_v3_1":520,"cvss_v4_0":9},{"baseScore":516,"baseSeverity":9,"vectorString":517,"impactScore":518,"exploitabilityScore":519},5,"AV:N/AC:L/Au:N/C:N/I:N/A:P",2.9,10,{"baseScore":110,"baseSeverity":521,"vectorString":113,"impactScore":522,"exploitabilityScore":519},"HIGH",6,{"source":124,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":524,"cvss_v4_0":9},{"baseScore":110,"baseSeverity":9,"vectorString":113,"impactScore":522,"exploitabilityScore":519},[526,537,545,558,570,576],{"ecosystem":9,"name":527,"vendor":528,"product":529,"cpe_part":530,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":531},"debian linux","debian","debian_linux","o",[532,535],{"version":533,"is_range":106,"range_type":534,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"9.0","cpe",{"version":536,"is_range":106,"range_type":534,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.0",{"ecosystem":9,"name":538,"vendor":539,"product":538,"cpe_part":530,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":540},"fedora","fedoraproject",[541,543],{"version":542,"is_range":106,"range_type":534,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"31",{"version":544,"is_range":106,"range_type":534,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"32",{"ecosystem":546,"name":547,"vendor":548,"product":549,"cpe_part":9,"purl_type":550,"purl_namespace":548,"purl_name":549,"source":9,"versions":551},"Go","github.com/ulikunitz/xz","github.com/ulikunitz","xz","golang",[552],{"version":553,"is_range":554,"range_type":555,"version_start":9,"version_start_type":9,"version_end":556,"version_end_type":557,"fixed_in":9},"lt0_5_8",true,"semver","0.5.8","excluding",{"ecosystem":9,"name":559,"vendor":550,"product":559,"cpe_part":560,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":561},"go","a",[562,565],{"version":563,"is_range":554,"range_type":534,"version_start":9,"version_start_type":9,"version_end":564,"version_end_type":557,"fixed_in":9},"lt1.13.15","1.13.15",{"version":566,"is_range":554,"range_type":534,"version_start":567,"version_start_type":568,"version_end":569,"version_end_type":557,"fixed_in":9},"gte1.14_lt1.14.7","1.14","including","1.14.7",{"ecosystem":546,"name":571,"vendor":546,"product":571,"cpe_part":9,"purl_type":550,"purl_namespace":9,"purl_name":571,"source":9,"versions":572},"stdlib",[573],{"version":574,"is_range":554,"range_type":555,"version_start":575,"version_start_type":568,"version_end":569,"version_end_type":557,"fixed_in":9},"gte1_14_0_0_lt1_14_7","1.14.0-0",{"ecosystem":9,"name":577,"vendor":578,"product":577,"cpe_part":530,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":579},"leap","opensuse",[580,582],{"version":581,"is_range":106,"range_type":534,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"15.1",{"version":583,"is_range":106,"range_type":534,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"15.2"]