Go standard library encoding/xml
1 known vulnerability in Go standard library encoding/xml, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-56859 CVSS 7.5 high Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.