CVE-2026-6653

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
References
Link Resource
https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260 Exploit Issue Tracking Third Party Advisory
https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058 Exploit Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

History

14 Jul 2026, 16:00

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
References () https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260 - () https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260 - Exploit, Issue Tracking, Third Party Advisory
References () https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058 - () https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058 - Exploit, Issue Tracking, Patch
First Time Xmlsoft libxml2
Xmlsoft

22 Jun 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 14:17

Updated : 2026-07-14 16:00


NVD link : CVE-2026-6653

Mitre link : CVE-2026-6653

CVE.ORG link : CVE-2026-6653


JSON object : View

Products Affected

xmlsoft

  • libxml2
CWE
CWE-416

Use After Free

CWE-611

Improper Restriction of XML External Entity Reference