Out-of-bounds Read Vulnerability in libxml2 by GNOME
CVE-2026-86137

2.9LOW

Key Information:

Vendor

Xmlsoft

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86137?

The vulnerability in libxml2 allows for an out-of-bounds read due to a flaw in the xmlFAParsePosCharGroup function, specifically within the handling of the NXT macro in xmlregexp. This could potentially expose sensitive data or lead to application instability. Users of affected libxml2 versions prior to 2.15.4 should take immediate measures to upgrade to mitigate any associated risks.

Affected Version(s)

libxml2 0 < 2.15.4

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.