CVE-2026-86138
published 2026-09-05CVE-2026-86138: In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
PriorityP335medium6.9CVSS 3.1
AVLACHPRNUINSUCHIHAL
EPSS
0.12%
2.0th percentile
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xmlsoft | libxml2 | < 2.15.4 | 2.15.4 |
| xmlsoft | libxml2 | — | — |
CVSS provenance
nvdv3.16.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow
vendor_redhat·2026-09-05·CVSS 6.9
CVE-2026-86138 [MEDIUM] CWE-787 libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow
libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow
A flaw was found in libxml2. The `xmlDictAddQString` function in `dict.c` is vulnerable to an integer overflow, which can lead to a heap-based buffer overflow. This vulnerability could allow a local attacker to achieve arbitrary code execution.
Package: libxml2 (Red Hat Hardened Images) - Affected
Package: swift-lang (Red Hat Hardened Images) - Affected
GHSA
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
ghsa_unreviewed·2026-09-05
CVE-2026-86138 [MEDIUM] CWE-190 In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-86138 pcem: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86138 [MEDIUM] CVE-2026-86138 pcem: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
CVE-2026-86138 pcem: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Bugzilla
CVE-2026-86138 qt6-qtwebengine: libxml2: Arbitrary code execution via heap-based buffer overflow [epel-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86138 [MEDIUM] CVE-2026-86138 qt6-qtwebengine: libxml2: Arbitrary code execution via heap-based buffer overflow [epel-all]
CVE-2026-86138 qt6-qtwebengine: libxml2: Arbitrary code execution via heap-based buffer overflow [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Bugzilla
CVE-2026-86138 mingw-libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86138 [MEDIUM] CVE-2026-86138 mingw-libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
CVE-2026-86138 mingw-libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Bugzilla
CVE-2026-86138 libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86138 [MEDIUM] CVE-2026-86138 libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
CVE-2026-86138 libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Bugzilla
CVE-2026-86138 qt5-qtwebengine: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86138 [MEDIUM] CVE-2026-86138 qt5-qtwebengine: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
CVE-2026-86138 qt5-qtwebengine: libxml2: Arbitrary code execution via heap-based buffer overflow [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Bugzilla
CVE-2026-86138 mingw-libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow [epel-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86138 [MEDIUM] CVE-2026-86138 mingw-libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow [epel-all]
CVE-2026-86138 mingw-libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Bugzilla
CVE-2026-86138 qt5-qtwebengine: libxml2: Arbitrary code execution via heap-based buffer overflow [epel-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86138 [MEDIUM] CVE-2026-86138 qt5-qtwebengine: libxml2: Arbitrary code execution via heap-based buffer overflow [epel-all]
CVE-2026-86138 qt5-qtwebengine: libxml2: Arbitrary code execution via heap-based buffer overflow [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Bugzilla
CVE-2026-86138 libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow
bugzilla·2026-09-05·CVSS 6.9
CVE-2026-86138 [MEDIUM] CVE-2026-86138 libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow
CVE-2026-86138 libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
2026-09-05
Published