Highlights
XML Validation Bypass: 1 prior fix. Scrutinize any change in this area.
etree.go: most-fixed (1 issue). Treat as high-risk during review.
0 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
XML Validation Bypass: Processing unseekable io.Reader streams directly can lead to a validation bypass because the parser or validator may consume or miss parts of the stream, failing to inspect the complete payload. Buffering the full stream to a temporary buffer before validation is required to ensure consistent validation state.