XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences.
A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory.
Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade perl-XML-LibXML | Jul 16, 2026 | Jul 14, 2026 |
| Amazon Linux Ami 2 | — | Upgrade perl-XML-LibXML-debuginfoUpgrade perl-XML-LibXML | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-XML-LibXML-testsUpgrade perl-XML-LibXMLUpgrade perl-XML-LibXML-debuginfoUpgrade perl-XML-LibXML-debugsource | Jun 9, 2026 | May 10, 2026 |
| Debian | — | Upgrade libxml-libxml-perl | Jul 12, 2026 | Jul 12, 2026 |
| Redhat_linux | — | No solution existsUpgrade perl-XML-LibXML-debugsourceUpgrade perl-XML-LibXML-debuginfoUpgrade perl-XML-LibXML | Jul 16, 2026 | May 10, 2026 |
| Rocky_linux | — | Upgrade perl-XML-LibXML-debuginfoUpgrade perl-XML-LibXML-debugsourceUpgrade perl-XML-LibXML | Jul 17, 2026 | Jul 16, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub