cbcvebase.
CVE-2026-6732
published 2026-04-23

CVE-2026-6732: A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.63%
46.6th percentile
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

Affected

14 ranges
VendorProductVersion rangeFixed in
ibmaix
ibmaix>= 7.2.5 < 7.2.5.127.2.5.12
ibmaix>= 7.3.2 < 7.3.3.37.3.3.3
ibmvios
ibmvios>= 4.1.0 < 4.1.1.304.1.1.30
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatopenshift_container_platform
ubuntulibxml2
xmlsoftlibxml2
xmlsoftlibxml2>= 2.13.0 < 2.15.32.15.3

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
vendor_ubuntu6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.