Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-0992

Опубликовано: 15 янв. 2026
Источник: nvd
CVSS3: 2.9
EPSS Низкий

Описание

A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_core_services:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.1.30 (исключая)
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
Версия от 7.2.5 (включая) до 7.2.5.12 (исключая)
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
Версия от 7.3.2 (включая) до 7.3.3.3 (исключая)
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
Версия до 2.15.2 (исключая)

EPSS

Процентиль: 34%
0.0041
Низкий

2.9 Low

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 2.9
ubuntu
7 месяцев назад

A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.

CVSS3: 2.9
redhat
7 месяцев назад

A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.

CVSS3: 2.9
msrc
7 месяцев назад

Libxml2: libxml2: denial of service via crafted xml catalogs

CVSS3: 2.9
debian
7 месяцев назад

A flaw was found in the libxml2 library. This uncontrolled resource co ...

CVSS3: 2.9
github
7 месяцев назад

A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.

EPSS

Процентиль: 34%
0.0041
Низкий

2.9 Low

CVSS3

Дефекты

CWE-400