CVE-2026-6653
published 2026-06-22CVE-2026-6653: Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.35%
27.2th percentile
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnome | libxml2 | >= 2.9.11 < 2.11.0 | 2.11.0 |
| ubuntu | libxml2 | — | — |
| xmlsoft | libxml2 | — | — |
| xmlsoft | libxml2 | 2.9.11 – 2.11.0 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.0HIGHCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free
vendor_redhat·2026-06-22·CVSS 7.0
CVE-2026-6653 [HIGH] CWE-416 libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free
libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
A flaw was found in libxml2. A remote attacker can exploit a use-after-free vulnerability in the `xmlParseInternalSubset` function by providing maliciously crafted XML input. This improper handling of entity resolution can lead to a denial-of-service (DoS), making the affected system or application unavailable.
Statement: This Moderate impact use-after-free vulnerability in libxml2 can lead to a denial of service in Red Hat products that process untrusted XML input. In the
Ubuntu
libxml2 vulnerability
vendor_ubuntu·2026-06-22
CVE-2026-6653 libxml2 vulnerability
Title: libxml2 vulnerability
Summary: libxml2 could be made to crash or run programs if it received specially
crafted input.
Geoffrey Humphreys discovered that libxml2 had a use after free when
parsing the internal subset of a DTD. A remote attacker could possibly use
this issue to cause a denial of service or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
VulDB
GNOME libxml2 up to 2.10.x XML use after free (Nessus ID 321971)
vuldb·2026-06-23·CVSS 7.0
CVE-2026-6653 [HIGH] GNOME libxml2 up to 2.10.x XML use after free (Nessus ID 321971)
A vulnerability was found in GNOME libxml2 up to 2.10.x. It has been rated as critical. The impacted element is an unknown function of the component XML Handler. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2026-6653. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper ent
ghsa_unreviewed·2026-06-22
CVE-2026-6653 [HIGH] CWE-416 Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper ent
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
No detection rules found.
No public exploits indexed.
2026-06-22
Published