Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86144

Опубликовано: 05 сент. 2026
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

A flaw in libxml2's XInclude processing (xmlXIncludeProcess and xmlXIncludeProcessTree) fails to propagate parser flags like XML_PARSE_NONET. This allows custom resource loaders to fetch external network resources, potentially enabling Server-Side Request Forgery (SSRF), XML External Entity (XXE) injection, or Denial of Service (DoS) attacks.

Отчет

A Moderate-severity flaw in libxml2 XInclude processing allows custom resource loaders to bypass network restriction flags, enabling unintended external network connections that could cause SSRF, information disclosure, or Denial of Service (DoS). Exploitation requires local access alongside high attack complexity, limiting its immediate widespread impact.

Меры по смягчению последствий

Do not expand untrusted XInclude; parse without XML_PARSE_XINCLUDE and do not call xmlXIncludeProcess / xmlXIncludeProcessTree. If XInclude is required, pass XML_PARSE_NONET (and XML_PARSE_NO_XXE where available) via xmlXIncludeProcessFlags, and restrict outbound fetches.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libxml2Fix deferred
Red Hat Enterprise Linux 10podmanNot affected
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Out of support scope
Red Hat Enterprise Linux 8container-tools:rhel8/podmanNot affected
Red Hat Enterprise Linux 8libxml2Affected
Red Hat Enterprise Linux 9libxml2Fix deferred
Red Hat Enterprise Linux 9podmanNot affected
Red Hat Hardened Imagesswift-langNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-669
https://bugzilla.redhat.com/show_bug.cgi?id=2528992libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation.

EPSS

Процентиль: 6%
0.00161
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
ubuntu
9 дней назад

(In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXInclu ...)

CVSS3: 5.6
nvd
11 дней назад

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

msrc
8 дней назад

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

CVSS3: 5.6
debian
11 дней назад

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXInclu ...

CVSS3: 5.6
github
11 дней назад

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

EPSS

Процентиль: 6%
0.00161
Низкий

5.6 Medium

CVSS3