CVE-2026-19201
Analyzed Analyzed - Analysis Complete

Uncontrolled Recursion in go-attestation Windows SIPA Parser

Vulnerability report for CVE-2026-19201, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-24

Assigner: Google Inc.

Description

An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation function recurses for every nested elamAggregation sub-event without enforcing a maximum recursion depth limit, while the size guard is bypassed on recursive execution paths. By submitting a crafted Windows event log containing deeply nested elamAggregation headers, an attacker can exhaust the goroutine call stack, triggering an unrecoverable fatal runtime error (stack overflow) that immediately crashes the verifier application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-24
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google go-attestation to 0.6.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an uncontrolled recursion issue in the Windows SIPA event log parser of Google go-attestation versions up to 0.6.1. The parser's function recurses without a depth limit when processing nested elamAggregation sub-events, allowing attackers to craft logs that exhaust the goroutine call stack. This triggers a stack overflow, crashing the verifier application and causing a denial of service.

Detection Guidance

This vulnerability is specific to the go-attestation library's Windows SIPA event log parser. Detection requires checking if your system uses a vulnerable version of go-attestation (up to 0.6.1). Inspect installed packages or binaries for go-attestation and verify version numbers. No direct network detection commands are provided in the context.

Impact Analysis

If you use the vulnerable go-attestation library, an attacker could exploit this flaw by submitting a specially crafted Windows event log. This would crash the application processing the log, leading to service disruption. The impact is limited to applications using the affected library versions.

Compliance Impact

This vulnerability causes a denial of service by crashing the verifier application through stack overflow, which could disrupt logging and audit processes. Compliance with GDPR or HIPAA may require continuous logging and audit functionality, so such disruptions could lead to non-compliance if systems fail to maintain required records or fail to detect security events.

Mitigation Strategies

Upgrade to go-attestation version 0.6.2 or later, which includes a recursion depth limit and other fixes. If upgrading is not immediately possible, avoid processing Windows event logs with deeply nested elamAggregation headers until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19201. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart