Inconsistency in Write Callbacks in libxml2 Affects XML Processing
CVE-2026-86143

6.9MEDIUM

Key Information:

Vendor

Xmlsoft

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86143?

The vulnerability in libxml2 affects the xmlIO component, where an inconsistency related to xmlOutputWriteCallback and xmlBufUse can lead to negative lengths being sent to write callbacks. This issue arises from insufficient checks for integer overflow prior to invoking these callbacks, which may compromise the security integrity of applications utilizing this library for XML processing. It highlights the importance of validating data lengths in callback functions to prevent potential exploitation in various contexts.

Affected Version(s)

libxml2 0 < 2.15.4

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.