xmlsoft libxml2

9 known vulnerabilities in xmlsoft libxml2, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-86144 CVSS 7.8 high In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security…
  • CVE-2026-86143 CVSS 7.3 high In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write…
  • CVE-2026-86142 CVSS 7.8 high In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
  • CVE-2026-86141 CVSS 3.3 low xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not…
  • CVE-2026-86140 CVSS 7.8 high In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
  • CVE-2026-86139 CVSS 7.8 high In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
  • CVE-2026-86138 CVSS 7.8 high In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
  • CVE-2026-86137 CVSS 6.1 medium In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
  • CVE-2026-11979 CVSS 1.8 low libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell()…