A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libxml2-develUpgrade libxml2-pythonUpgrade libxml2-staticUpgrade libxml2-debuginfoUpgrade libxml2 | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade libxml2-staticUpgrade python3-libxml2-debuginfoUpgrade libxml2Upgrade libxml2-develUpgrade libxml2-debuginfoUpgrade python3-libxml2Upgrade libxml2-debugsource | Feb 10, 2026 | Jan 15, 2026 |
| Debian | — | Upgrade libxml2 | Jun 9, 2026 | Jun 9, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade python3-libxml2Upgrade libxml2 | Mar 10, 2026 | Mar 10, 2026 |
| Ibm Aix | — | Apply the fix or workaround for libxml2_advisory11 | May 31, 2026 | May 28, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 15, 2026 |
| Suse | — | Upgrade libxslt1Upgrade libexslt0Upgrade python-libxml2Upgrade python3-libxml2-pythonUpgrade libxml2-devel-32bitUpgrade libxml2-develUpgrade libxslt-toolsUpgrade libxml2-docUpgrade python3-libxml2Upgrade libxml2-toolsUpgrade libxml2-2Upgrade libxml2-2-32bitUpgrade libxslt-develUpgrade python311-libxml2Upgrade python313-libxml2 | Feb 18, 2026 | Feb 17, 2026 |
| Ubuntu | — | Upgrade libxml2-16Upgrade libxml2 (Ubuntu Pro)Upgrade libxml2 | Jan 23, 2026 | Jan 15, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 29, 2026 | Jan 15, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub