CVE-2022-28131 | Google Go up to 1.17.11/1.18.3 XML Document Decoder.Skip recursion (Nessus ID 211529 / WID-SEC-2022-0879)
A vulnerability was found in Google Go up to 1.17.11/1.18.3. It has been rated as problematic. Affected by this vulnerability is the function Decoder.Skip of the component XML Document Handler. The manipulation leads to uncontrolled recursion.
This vulnerability is traded as CVE-2022-28131. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.