CVE-2026-0990

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.
References
Link Resource
https://access.redhat.com/errata/RHSA-2026:7519 Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-0990 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2429959 Issue Tracking Third Party Advisory
https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_core_services:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

History

30 Jun 2026, 20:18

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2026:7519 - () https://access.redhat.com/errata/RHSA-2026:7519 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2026-0990 - () https://access.redhat.com/security/cve/CVE-2026-0990 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2429959 - () https://bugzilla.redhat.com/show_bug.cgi?id=2429959 - Issue Tracking, Third Party Advisory
References () https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018 - () https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018 - Exploit, Issue Tracking, Third Party Advisory
CPE cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_core_services:-:*:*:*:*:*:*:*
First Time Ibm aix
Redhat enterprise Linux
Redhat hardened Images
Redhat jboss Core Services
Xmlsoft libxml2
Xmlsoft
Redhat
Ibm
Redhat openshift Container Platform
Ibm vios

22 Apr 2026, 10:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:7519 -

09 Apr 2026, 18:16

Type Values Removed Values Added
References
  • () https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018 -
Summary
  • (es) Se encontró una falla en libxml2, una biblioteca de análisis XML. Esta vulnerabilidad de recursión incontrolada ocurre en la función xmlCatalogXMLResolveURI cuando un catálogo XML contiene una entrada URI delegada que se referencia a sí misma. Un atacante remoto podría explotar este problema dependiente de la configuración al proporcionar un catálogo XML especialmente diseñado, lo que lleva a una recursión infinita y al agotamiento de la pila de llamadas. Esto finalmente resulta en una falla de segmentación, causando una denegación de servicio (DoS) al bloquear las aplicaciones afectadas.

15 Jan 2026, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 15:15

Updated : 2026-06-30 20:18


NVD link : CVE-2026-0990

Mitre link : CVE-2026-0990

CVE.ORG link : CVE-2026-0990


JSON object : View

Products Affected

ibm

  • vios
  • aix

redhat

  • openshift_container_platform
  • hardened_images
  • jboss_core_services
  • enterprise_linux

xmlsoft

  • libxml2
CWE
CWE-674

Uncontrolled Recursion