Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6732

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

Отчет

Per upstream:

It's NOT recommended to use this software to process untrusted data. There is a lot of ways that a malicious crafted xml could exploit a hidden vulnerability in the software.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libxml2Fix deferred
Red Hat Enterprise Linux 6libxml2Fix deferred
Red Hat Enterprise Linux 7libxml2Fix deferred
Red Hat Enterprise Linux 8libxml2Fix deferred
Red Hat Enterprise Linux 9libxml2Fix deferred
Red Hat JBoss Core Serviceslibxml2Fix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imageslibxml2-main-2.15.3-0.1.hum1FixedRHSA-2026:1150329.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2461300libxml2: libxml2: Denial of Service via crafted XSD-validated document

EPSS

Процентиль: 46%
0.00632
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

CVSS3: 6.5
nvd
3 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

msrc
3 месяца назад

Libxml2: libxml2: denial of service via crafted xsd-validated document

CVSS3: 6.5
debian
3 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the librar ...

CVSS3: 6.5
github
3 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

EPSS

Процентиль: 46%
0.00632
Низкий

6.5 Medium

CVSS3