Due to improper input sanitization, a maliciously constructed filename could cause a file download to use an attacker controlled filename, as well as injecting additional headers into an HTTP response.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2021-0108" }