CVSS v3
7.3
HIGH
EPSS Score
3.2 %
exploit probability, as of 2026-09-25
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.
Technical details
- Published
- 2021-08-02
Frequently asked questions
What is CVE-2021-33195?
Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.
Is CVE-2021-33195 actively exploited?
Active exploitation of CVE-2021-33195 has not been confirmed. Its EPSS score was 3.2% on 2026-09-25, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2021-33195?
CVE-2021-33195 has a CVSS v3 base score of 7.3 (HIGH severity).
Is CVE-2021-33195 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2021 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).