xmlsoft / libxml2
14 known vulnerabilities in xmlsoft libxml2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-6021 | Medium | 1.4% | 7.5 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in… | |
| CVE-2026-86140 | Medium | 0.1% | 8.0 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-base… | |
| CVE-2026-0990 | Low | 0.9% | 5.9 | A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion… | |
| CVE-2026-6732 | Low | 0.6% | 6.5 | A flaw was found in libxml2. This vulnerability occurs when the library processe… | |
| CVE-2026-0989 | Low | 0.5% | 3.7 | A flaw was identified in the RelaxNG parser of libxml2 related to how external s… | |
| CVE-2026-0992 | Low | 0.5% | 2.9 | A flaw was found in the libxml2 library. This uncontrolled resource consumption … | |
| CVE-2025-6170 | Low | 0.3% | 2.5 | A flaw was found in the interactive shell of the xmllint command-line tool, used… | |
| CVE-2026-86144 | Low | 0.2% | 5.6 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessT… | |
| CVE-2026-86142 | Low | 0.2% | 6.9 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXP… | |
| CVE-2026-86137 | Low | 0.1% | 2.9 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka … | |
| CVE-2026-86143 | Low | 0.1% | 6.9 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback an… | |
| CVE-2026-86138 | Low | 0.1% | 6.9 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow an… | |
| CVE-2026-86141 | Low | 0.1% | 2.9 | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewPa… | |
| CVE-2026-86139 | Low | 0.1% | 6.9 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. |