UNKNOWN Go
Add recursion depth guard during decode in encoding/xml
GO-2026-6088 · BIT-golang-2026-56859 · CVE-2026-56859
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes