Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56859

Опубликовано: 13 авг. 2026
Источник: debian
EPSS Низкий

Описание

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.27fixed1.27~rc3-1package
golang-1.26fixed1.26.6-1package
golang-1.25fixed1.25.13-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.15removedpackage

Примечания

  • https://github.com/golang/go/issues/80481

  • Fixed by: https://github.com/golang/go/commit/d5eeaa7de337f01173036096619cba09e31bde1a (go1.27rc3)

  • Fixed by: https://github.com/golang/go/commit/9918f26ab31a6bf9209ecc06465cab0e287e90f1 (go1.26.6)

  • Fixed by: https://github.com/golang/go/commit/b952d04e2ab03d7b9049b2909e66dc91707089b4 (go1.25.13)

EPSS

Процентиль: 45%
0.00568
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
23 дня назад

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

CVSS3: 7.5
redhat
23 дня назад

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

CVSS3: 7.5
nvd
23 дня назад

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

msrc
16 дней назад

Add recursion depth guard during decode in encoding/xml

CVSS3: 7.5
github
23 дня назад

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

EPSS

Процентиль: 45%
0.00568
Низкий