Gnome Libxml2 vulnerabilities
3 known vulnerabilities affecting gnome/libxml2.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-6653P3CRITICALCVSS 9.8≥ 2.9.11, < 2.11.02026-06-22
CVE-2026-6653 [CRITICAL] CWE-416 CVE-2026-6653: Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allow
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
nvd
CVE-2025-7425P3HIGHCVSS 7.8fixed in 2.15.22025-07-10
CVE-2025-7425 [HIGH] CWE-416 CVE-2025-7425: A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrup
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers t
nvd
CVE-2025-49795P3HIGHCVSS 7.5≥ 2.10.0, < 2.14.52025-06-16
CVE-2025-49795 [HIGH] CWE-825 CVE-2025-49795: A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions.
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
nvd