Junglewise Threat Intelligence

CVE-2026-56859: Go DecodeElement stack exhaustion vulnerability

CVE-2026-56859 · Severity: high · CVSS 7.5 · Published 2026-08-13

Vendors: Google.

Executive brief

A vulnerability in Go's XML processing component allows attackers to cause a denial of service by exhausting the application's stack memory. The DecodeElement function fails to properly enforce recursion depth limits, permitting an attacker to trigger uncontrolled memory consumption and crash the affected service.

Technical details

The vulnerability exists in Go's XML decoding functionality, specifically in the DecodeElement function which handles recursive XML element parsing. The function improperly resets an internal depth counter, preventing the depth limit check from ever triggering. An attacker can craft a malicious XML document with deeply nested elements that bypasses the recursion limit, causing unbounded stack growth and leading to stack exhaustion. The vulnerability is triggered via network-supplied XML input without requiring authentication or special privileges. A patch addressing the depth counter reset logic is available in Go's repository.

Affected products

  • Google Go <unknown>

Timeline

  • 2026-08-13: disclosed

References