A vulnerability, which was classified as problematic, was found in Go encoding and xml up to 1.25.12/1.26.5. This affects the function
DecodeElement. Such manipulation leads to allocation of resources.
This vulnerability is referenced as CVE-2026-56859. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.