Skip to content

encoding/xml: stack exhaustion in Decoder.Skip #53614

Closed
@tatianab

Description

Calling Decoder.Skip when parsing a deeply nested XML document can cause a panic due to stack exhaustion.

The Go Security team discovered this issue, and it was independently reported by Juho Nurminen of Mattermost.

This is CVE-2022-28131.

(This was a PRIVATE issue tracked in http://b/227192220 and fixed by http://tg/1419912.)

/cc @golang/security and @golang/release

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions