CVE-2026-6653
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
- Published Jun 22, 2026
- CVSS 7.0 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available
- A fix is available