CVE-2026-86139
published 2026-09-05CVE-2026-86139: In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
PriorityP430medium6.9CVSS 3.1
AVLACHPRNUINSUCHIHAL
EPSS
0.11%
1.3th percentile
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xmlsoft | libxml2 | < 2.15.4 | 2.15.4 |
| xmlsoft | libxml2 | — | — |
CVSS provenance
nvdv3.16.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libxml2: libxml2: Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution
vendor_redhat·2026-09-05·CVSS 6.9
CVE-2026-86139 [MEDIUM] CWE-190 libxml2: libxml2: Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution
libxml2: libxml2: Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution
A flaw was found in libxml2. An integer overflow vulnerability exists in the `xmlURIEscapeStr` function within `uri.c`. This flaw could potentially lead to memory corruption, allowing an attacker to achieve information disclosure or arbitrary code execution.
Package: libxml2 (Red Hat Hardened Images) - Affected
Package: swift-lang (Red Hat Hardened Images) - Affected
GHSA
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
ghsa_unreviewed·2026-09-05
CVE-2026-86139 [MEDIUM] CWE-190 In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
No detection rules found.
No public exploits indexed.
2026-09-05
Published