Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6rf6-xrp6-223m

Опубликовано: 24 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

EPSS

Процентиль: 46%
0.00632
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-843

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

CVSS3: 6.5
redhat
4 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

CVSS3: 6.5
nvd
3 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

msrc
3 месяца назад

Libxml2: libxml2: denial of service via crafted xsd-validated document

CVSS3: 6.5
debian
3 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the librar ...

EPSS

Процентиль: 46%
0.00632
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-843