A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qt6-qtwebengineUpgrade libxml2 | May 25, 2026 | Apr 23, 2026 |
| Ibm Aix | — | Apply the fix or workaround for libxml2_advisory11 | May 31, 2026 | May 28, 2026 |
| Redhat_linux | — | — | Jul 17, 2026 | Apr 16, 2026 |
| Ubuntu | — | Upgrade libxml2-sourceUpgrade python3-libxml2Upgrade libxml2-utilsUpgrade libxml2-16Upgrade libxml2-dev | Jun 23, 2026 | Jun 22, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 24, 2026 | Apr 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub