CVE-2026-86138: xmlsoft libxml2: In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | Rapid7 Vulnerability Database