A vulnerability, which was classified as problematic, was found in Go encoding and xml up to 1.25.12/1.26.5. This affects the function DecodeElement. Such manipulation leads to allocation of resources.

This vulnerability is referenced as CVE-2026-56859. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.