CVE-2026-86143
published 2026-09-05CVE-2026-86143: In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a…
PriorityP432medium6.9CVSS 3.1
AVLACHPRNUINSUCHIHAL
EPSS
0.12%
2.0th percentile
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xmlsoft | libxml2 | < 2.15.4 | 2.15.4 |
| xmlsoft | libxml2 | — | — |
CVSS provenance
nvdv3.16.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling
ghsa_unreviewed·2026-09-05
CVE-2026-86143 [MEDIUM] CWE-192 In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
VulDB
xmlsoft libxml2 up to 2.15.3 xmlIO xmlOutputWriteCallback integer overflow (Nessus ID 343104)
vuldb·2026-09-05·CVSS 6.9
CVE-2026-86143 [MEDIUM] xmlsoft libxml2 up to 2.15.3 xmlIO xmlOutputWriteCallback integer overflow (Nessus ID 343104)
A vulnerability classified as problematic was found in xmlsoft libxml2 up to 2.15.3. This impacts the function xmlOutputWriteCallback of the component xmlIO. The manipulation results in integer overflow.
This vulnerability is known as CVE-2026-86143. Attacking locally is a requirement. No exploit is available.
Upgrading the affected component is advised.
Red Hat
libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks
vendor_redhat·2026-09-05·CVSS 6.9
CVE-2026-86143 [MEDIUM] CWE-190 libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks
libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks
A flaw was found in libxml2. An integer overflow vulnerability exists in the xmlIO module, where an inconsistency between xmlOutputWriteCallback and xmlBufUse can cause negative length values to be passed to write callbacks. This occurs when the accumulated data backlog exceeds the maximum integer value. This issue can lead to an unsafe state in downstream callback logic, potentially resulting in data corruption or other integrity and confidentiality impacts.
Package: libxml2 (Red Hat Hardened Images) - Affected
Package: swift-lang (Red Hat Hardened Images) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-86143 mingw-libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86143 [MEDIUM] CVE-2026-86143 mingw-libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
CVE-2026-86143 mingw-libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Bugzilla
CVE-2026-86143 qt5-qtwebengine: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86143 [MEDIUM] CVE-2026-86143 qt5-qtwebengine: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
CVE-2026-86143 qt5-qtwebengine: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Bugzilla
CVE-2026-86143 mingw-libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks [epel-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86143 [MEDIUM] CVE-2026-86143 mingw-libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks [epel-all]
CVE-2026-86143 mingw-libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Bugzilla
CVE-2026-86143 pcem: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86143 [MEDIUM] CVE-2026-86143 pcem: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
CVE-2026-86143 pcem: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Bugzilla
CVE-2026-86143 qt5-qtwebengine: libxml2: Data integrity issues due to integer overflow in write callbacks [epel-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86143 [MEDIUM] CVE-2026-86143 qt5-qtwebengine: libxml2: Data integrity issues due to integer overflow in write callbacks [epel-all]
CVE-2026-86143 qt5-qtwebengine: libxml2: Data integrity issues due to integer overflow in write callbacks [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Bugzilla
CVE-2026-86143 qt6-qtwebengine: libxml2: Data integrity issues due to integer overflow in write callbacks [epel-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86143 [MEDIUM] CVE-2026-86143 qt6-qtwebengine: libxml2: Data integrity issues due to integer overflow in write callbacks [epel-all]
CVE-2026-86143 qt6-qtwebengine: libxml2: Data integrity issues due to integer overflow in write callbacks [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Bugzilla
CVE-2026-86143 libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
bugzilla·2026-09-09·CVSS 6.9
CVE-2026-86143 [MEDIUM] CVE-2026-86143 libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
CVE-2026-86143 libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Bugzilla
CVE-2026-86143 libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks
bugzilla·2026-09-05·CVSS 6.9
CVE-2026-86143 [MEDIUM] CVE-2026-86143 libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks
CVE-2026-86143 libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
2026-09-05
Published