{"record":{"id":"9e5db863c6beef67","repo":"gofiber/fiber","slug":"failed-to-unmarshal-xml-w","errorCode":null,"errorMessage":"failed to unmarshal xml: %w","messagePattern":"failed to unmarshal xml: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"binder/xml.go","lineNumber":22,"sourceCode":"\t\"fmt\"\n\n\t\"github.com/gofiber/utils/v2\"\n)\n\n// XMLBinding is the XML binder for XML request body.\ntype XMLBinding struct {\n\tXMLDecoder utils.XMLUnmarshal\n}\n\n// Name returns the binding name.\nfunc (*XMLBinding) Name() string {\n\treturn \"xml\"\n}\n\n// Bind parses the request body as XML and returns the result.\nfunc (b *XMLBinding) Bind(body []byte, out any) error {\n\tif err := b.XMLDecoder(body, out); err != nil {\n\t\treturn fmt.Errorf(\"failed to unmarshal xml: %w\", err)\n\t}\n\n\treturn nil\n}\n\n// Reset resets the XMLBinding binder.\nfunc (b *XMLBinding) Reset() {\n\tb.XMLDecoder = nil\n}\n","sourceCodeStart":4,"sourceCodeEnd":32,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/binder/xml.go#L4-L32","documentation":"XMLBinding.Bind wraps the underlying utils.XMLUnmarshal error when the request body cannot be decoded into the target struct. The wrapped error carries the raw decoder cause (syntax error, type mismatch, or unexpected EOF).","triggerScenarios":"A client sending malformed XML, truncated body, wrong encoding (e.g. UTF-16 BOM), or a body that does not map onto the out struct's fields/tags. Also triggered if XMLDecoder was replaced with a custom function that itself returns an error.","commonSituations":"Missing or wrong XML struct tags; client sends JSON with Content-Type: application/xml; partial read truncating the body; a Reset() leaving XMLDecoder nil and a default being supplied that is stricter than expected.","solutions":["Validate the request Content-Type is application/xml and the body is well-formed XML before binding (parse with xml.Unmarshal into a throwaway value or check the prolog).","Correct the target struct's xml tags to match the document.","If using a custom decoder, return a descriptive error and ensure it is set on XMLBinding.XMLDecoder."],"exampleFix":"// before\nvar p Payload\nif err := xmlBinder.Bind(body, &p); err != nil { ... }\n\n// after\nvar p Payload\nif err := xmlBinder.Bind(body, &p); err != nil {\n    if syntaxErr := (*xml.SyntaxError)(nil); errors.As(err, &syntaxErr) {\n        return fmt.Errorf(\"malformed xml from client: %w\", err)\n    }\n    return err\n}","handlingStrategy":"try-catch","validationCode":"// Cheap pre-check that the body parses as XML before binding:\nvar probe any\nif err := xml.Unmarshal(body, &probe); err != nil {\n    return fmt.Errorf(\"rejecting non-xml body: %w\", err)\n}","typeGuard":null,"tryCatchPattern":"if err := xmlBinder.Bind(body, &out); err != nil {\n    var se *xml.SyntaxError\n    if errors.As(err, &se) { /* malformed payload */ }\n    var te *xml.UnmarshalTypeError\n    if errors.As(err, &te) { /* struct/tag mismatch */ }\n    return err\n}","preventionTips":["Verify Content-Type is application/xml before attempting XML binding.","Keep struct xml tags in sync with the document; add integration tests using representative payloads.","Reject bodies that exceed a sane max size before decoding to limit attacker-controlled work."],"tags":["binder","xml","unmarshal","decoding"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}