Xmlsoft
Xmlsoft Libxml2: vulnerabilities and CVEs
Xmlsoft Libxml2 has 122 published vulnerabilities, 18 of them in the last 12 months. 11 are rated critical and 0 are listed by CISA as actively exploited.
CVEs122
Last 12 months18
Critical11
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76781 | Medium (5.5) | 0.17% | — | Sep 17, 2026 | A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its… |
| CVE-2026-74860 | High (8.5) | 0.44% | — | Sep 8, 2026 | A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated… |
| CVE-2026-86144 | High (7.8) | 0.19% | — | Sep 5, 2026 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource… |
| CVE-2026-86143 | High (7.3) | 0.19% | — | Sep 5, 2026 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This… |
| CVE-2026-86142 | High (7.8) | 0.16% | — | Sep 5, 2026 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. |
| CVE-2026-86141 | Low (3.3) | 0.17% | — | Sep 5, 2026 | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking. |
| CVE-2026-86140 | High (7.8) | 0.16% | — | Sep 5, 2026 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. |
| CVE-2026-86139 | High (7.8) | 0.17% | — | Sep 5, 2026 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. |
| CVE-2026-86138 | High (7.8) | 0.13% | — | Sep 5, 2026 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. |
| CVE-2026-86137 | Medium (6.1) | 0.19% | — | Sep 5, 2026 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. |
| CVE-2026-11979 | Low (1.8) | 0.15% | — | Jun 29, 2026 | libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds… |
| CVE-2026-6653 | High (7) | 0.36% | — | Jun 22, 2026 | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution… |
| CVE-2026-48981 | Medium (6.7) | 0.15% | — | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb calls xmlReadFile() with flags=0 when loading the configuration file, allowing libxml2 to process… |
| CVE-2026-6732 | High (7.5) | 0.94% | — | Apr 23, 2026 | A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit… |
| CVE-2026-1757 | Medium (6.2) | 0.22% | — | Feb 2, 2026 | A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input… |
| CVE-2026-0992 | Low (2.9) | 0.46% | — | Jan 15, 2026 | A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A… |
| CVE-2026-0990 | Medium (5.9) | 0.97% | — | Jan 15, 2026 | A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A… |
| CVE-2026-0989 | Low (3.7) | 0.54% | — | Jan 15, 2026 | A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially… |
| CVE-2025-9714 | Medium (5.5) | 0.16% | — | Sep 10, 2025 | Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`,… |
| CVE-2025-8732 | Low (1.9) | 0.21% | — | Aug 8, 2025 | A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled… |
| CVE-2025-49796 | Critical (9.1) | 1.6% | — | Jun 16, 2025 | A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead… |
| CVE-2025-49795 | High (7.5) | 0.59% | — | Jun 16, 2025 | A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service. |
| CVE-2025-49794 | Critical (9.1) | 0.83% | — | Jun 16, 2025 | A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a… |
| CVE-2025-6170 | Low (2.5) | 0.32% | — | Jun 16, 2025 | A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it… |
| CVE-2025-6021 | High (7.5) | 1.4% | — | Jun 12, 2025 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when… |
| CVE-2025-32415 | High (7.5) | 0.58% | — | Apr 17, 2025 | In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with… |
| CVE-2025-32414 | High (7.5) | 0.37% | — | Apr 8, 2025 | In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and… |
| CVE-2025-27113 | High (7.5) | 1.1% | — | Feb 18, 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c. |
| CVE-2025-24928 | High (7.7) | 0.39% | — | Feb 18, 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is… |
| CVE-2024-56171 | Critical (9.8) | 1.2% | — | Feb 18, 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an… |