xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impact.
{
"github_reviewed": true,
"nvd_published_at": "2020-09-16T15:15:00Z",
"github_reviewed_at": "2022-10-07T07:20:03Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-119",
"CWE-20"
]
}