{"id":"CVE-2026-56859","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-56859","summary":"Add recursion depth guard during decode in encoding/xml","details":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.","published":"2026-08-13T21:43:54Z","modified":"2026-08-14T09:41:58.916583585Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"stdlib","fixedVersion":"1.25.13"}],"fix":null,"references":[{"type":"REPORT","url":"https://go.dev/issue/80481"},{"type":"FIX","url":"https://go.dev/cl/803320"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/94pEornpRlI"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T09:41:58.916583585Z"}}