7.5

CVE-2026-6732

Exploit

Libxml2: libxml2: denial of service via crafted xsd-validated document

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xmlsoft ≫ Libxml2 Version >= 2.13.0 < 2.15.3
Redhat ≫ Hardened Images Version -
Redhat ≫ Jboss Core Services Version -
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
Ibm ≫ Vios Version >= 4.1.0 < 4.1.1.30
Ibm ≫ Vios Version 4.1.2.0
Ibm ≫ Aix Version >= 7.2.5 < 7.2.5.12
Ibm ≫ Aix Version >= 7.3.2 < 7.3.3.3
Ibm ≫ Aix Version 7.3.4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.455
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
RedHat 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

https://bugzilla.redhat.com/show_bug.cgi?id=2461300
Third Party Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:11503
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-6732
Third Party Advisory
https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097
Third Party Advisory
Exploit
Issue Tracking
https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411
Third Party Advisory
Issue Tracking