CVE-2026-0989

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.
References
Link Resource
https://access.redhat.com/errata/RHSA-2026:7519 Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-0989 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2429933 Issue Tracking Third Party Advisory
https://gitlab.gnome.org/GNOME/libxml2/-/issues/998 Exploit Issue Tracking Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_core_services:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*

History

30 Jun 2026, 20:20

Type Values Removed Values Added
CPE cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_core_services:-:*:*:*:*:*:*:*
References () https://access.redhat.com/errata/RHSA-2026:7519 - () https://access.redhat.com/errata/RHSA-2026:7519 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2026-0989 - () https://access.redhat.com/security/cve/CVE-2026-0989 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2429933 - () https://bugzilla.redhat.com/show_bug.cgi?id=2429933 - Issue Tracking, Third Party Advisory
References () https://gitlab.gnome.org/GNOME/libxml2/-/issues/998 - () https://gitlab.gnome.org/GNOME/libxml2/-/issues/998 - Exploit, Issue Tracking, Mitigation, Third Party Advisory
First Time Ibm aix
Redhat enterprise Linux
Redhat hardened Images
Redhat jboss Core Services
Xmlsoft libxml2
Xmlsoft
Redhat
Ibm
Redhat openshift Container Platform
Ibm vios

22 Apr 2026, 10:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:7519 -

09 Apr 2026, 18:16

Type Values Removed Values Added
References
  • () https://gitlab.gnome.org/GNOME/libxml2/-/issues/998 -
Summary
  • (es) Se identificó un fallo en el analizador RelaxNG de libxml2 relacionado con la forma en que se gestionan las inclusiones de esquemas externos. El analizador no impone un límite en la profundidad de inclusión al resolver directivas anidadas. Esquemas especialmente elaborados o excesivamente complejos pueden causar recursión excesiva durante el análisis. Esto puede provocar el agotamiento de la pila y caídas de la aplicación, creando un riesgo de denegación de servicio.

15 Jan 2026, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 15:15

Updated : 2026-06-30 20:20


NVD link : CVE-2026-0989

Mitre link : CVE-2026-0989

CVE.ORG link : CVE-2026-0989


JSON object : View

Products Affected

redhat

  • openshift_container_platform
  • hardened_images
  • jboss_core_services
  • enterprise_linux

ibm

  • vios
  • aix

xmlsoft

  • libxml2
CWE
CWE-674

Uncontrolled Recursion