CVE-2026-56859
published 2026-08-13CVE-2026-56859: Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.57%
45.0th percentile
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
Affected
93 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3scale-amp2 | 3scale-operator-bundle | — | — |
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-main-rhel9 | — | — |
| albo | aws-load-balancer-operator | — | — |
| albo | aws-load-balancer-rhel8-operator | — | — |
| ansible-automation-platform-26 | receptor-rhel9 | — | — |
| ansible-automation-platform-27 | receptor-rhel9 | — | — |
| ansible-automation-platform | platform-operator-bundle | — | — |
| build-of-trustee | trustee-rhel9-operator | — | — |
| buildah_project | buildah | — | — |
| cert-manager | jetstack-cert-manager-rhel9 | — | — |
| compliance | openshift-compliance-operator-bundle | — | — |
| compliance | openshift-selinuxd-rhel8 | — | — |
| container-native-virtualization | kubemacpool-rhel9 | — | — |
| container-tools_rhel8 | buildah | — | — |
| container-tools_rhel8 | conmon | — | — |
| container-tools_rhel8 | containernetworking-plugins | — | — |
| container-tools_rhel8 | podman | — | — |
| container-tools_rhel8 | skopeo | — | — |
| container-tools_rhel8 | toolbox | — | — |
| cryostat | cryostat-storage-rhel9 | — | — |
| custom-metrics-autoscaler | custom-metrics-autoscaler-rhel9 | — | — |
| devspaces | udi-rhel9 | — | — |
| devworkspace | devworkspace-rhel9-operator | — | — |
| dvo | deployment-validation-rhel8-operator | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
vendor_redhat·2026-08-13·CVSS 7.5
CVE-2026-56859 [HIGH] CWE-776 encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
A flaw was found in the `encoding/xml` package of Go. The `DecodeElement` function failed to correctly track recursion depth, which could lead to stack exhaustion. A remote attacker could exploit this vulnerability by providing a specially crafted XML input, resulting in a Denial of Service (DoS) for the affected application.
Package: rhai/assisted-installer-rhel9 (Assisted Installer for Red Hat OpenShift Container Platform 2) - Affected
Package: albo/aws-load-balancer-operator (AWS Load Balancer Operator) - Affected
Package: albo/aws-load-balancer-rhel8-operator (AWS Load Balancer Operator) - Affected
Package: openshift-builds/openshift-builds-waiters-rhel9 (Builds for Red Hat OpenShift) - Affected
Pa
VulDB
Go encoding/xml up to 1.25.12/1.26.5 DecodeElement allocation of resources
vuldb·2026-08-14
CVE-2026-56859 [LOW] Go encoding/xml up to 1.25.12/1.26.5 DecodeElement allocation of resources
A vulnerability, which was classified as problematic, was found in Go encoding and xml up to 1.25.12/1.26.5. This affects the function DecodeElement. Such manipulation leads to allocation of resources.
This vulnerability is referenced as CVE-2026-56859. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
GHSA
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
ghsa_unreviewed·2026-08-14
CVE-2026-56859 Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
No detection rules found.
No public exploits indexed.
2026-08-13
Published