Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-0989

Опубликовано: 15 янв. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
Версия до 2.15.2 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_core_services:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.1.30 (исключая)
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
Версия от 7.2.5 (включая) до 7.2.5.12 (исключая)
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
Версия от 7.3.2 (включая) до 7.3.3.3 (исключая)
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00438
Низкий

3.7 Low

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 3.7
ubuntu
7 месяцев назад

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.

CVSS3: 3.7
redhat
7 месяцев назад

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.

CVSS3: 3.7
msrc
7 месяцев назад

Libxml2: unbounded relaxng include recursion leading to stack overflow

CVSS3: 3.7
debian
7 месяцев назад

A flaw was identified in the RelaxNG parser of libxml2 related to how ...

suse-cvrf
6 месяцев назад

Security update for libxml2

EPSS

Процентиль: 36%
0.00438
Низкий

3.7 Low

CVSS3

Дефекты

CWE-674