VDB
CVE-2026-56859
CVE-2026-56859
PUBLISHED
CVSS 7.5 HIGH
Reported by Go · Published August 13, 2026
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Go standard library | encoding/xml | 0, 1.26.0-0, 1.27.0-0 |
| chainguard | dapr-fips-1.18 | 0 |
| chainguard | coder-fips-2.29 | 0 |
| chainguard | cluster-proportional-vertical-autoscaler | 0 |
| chainguard | opentelemetry-collector-contrib | 0 |
| chainguard | fleet-server-9.5 | * |
| chainguard | eks-distro-1.33 | 0 |
| chainguard | terraform-provider-google-fips | * |
| chainguard | tekton-pipelines-1.12 | * |
| chainguard | crossplane-provider-aws-keyspaces | 0 |
| chainguard | crossplane-provider-azure-keyvault | 0 |
| chainguard | terraform-1.14 | 0 |
| wolfi | weaviate | 0, 0, 0 |
| chainguard | crossplane-provider-aws-lightsail | 0 |
| chainguard | go-discover-fips | 0 |
| wolfi | gobuster | 0, 0, 0 |
| chainguard | azure-container-networking | 0 |
| chainguard | rclone | 0, 0 |
| chainguard | pombump | 0 |
| chainguard | milvus-2.6 | *, * |
…and 2819 more
Timeline
- Aug 13, 2026 CVE Published
- Aug 14, 2026 CVE Updated
- Aug 15, 2026 Coalition ESS Score
- Aug 20, 2026 Security Advisory
- Aug 24, 2026 EPSS Score