xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impact.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/antchfx/xmlquery(Go) | 0 | 1.3.1 | N/A |
CVSS Metrics