Go standard library encoding/xml

1 known vulnerability in Go standard library encoding/xml, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-56859 CVSS 7.5 high Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.