CVE-2026-32287

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
2
PROJECTS

Description

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

[mirror] The Go Vulnerability Database
GitHubGitHub
601
XPath package for golang, supports HTML, XML, JSON document query and more
GitHubGitHub
740