CVE-2026-76781
A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).
- Published Sep 17, 2026
- CVSS 5.5 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available