Xmlsoft Libxml2 vulnerabilities
135 known vulnerabilities affecting xmlsoft/libxml2.
Total CVEs
135
CISA KEV
0
Public exploits
8
Exploited in wild
2
Severity breakdown
CRITICAL17HIGH50MEDIUM60LOW7UNKNOWN1
Vulnerabilities
Page 7 of 7
CVE-2017-5969P4MEDIUMCVSS 4.7v2.9.42017-04-11
CVE-2017-5969 [MEDIUM] CWE-476 CVE-2017-5969: libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL
libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.
nvdosv
CVE-2013-0338P4MEDIUMCVSS 4.3≤ 2.9.0v1.7.0+123 more2013-04-25
CVE-2013-0338 [MEDIUM] CWE-119 CVE-2013-0338: libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and m
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.
nvdosv
CVE-2011-3905P4MEDIUMCVSS 5.0≥ 0, < 2.7.8.dfsg-5.12011-12-13
CVE-2011-3905 [MEDIUM] CVE-2011-3905: libxml2, as used in Google Chrome before 16
libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
osv
CVE-2015-8035P4LOWCVSS 2.6v2.9.12015-11-18
CVE-2015-8035 [LOW] CWE-399 CVE-2015-8035: The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, whic
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
nvdosv
CVE-2007-6284P4MEDIUMCVSS 5.0≥ 0, < 2.6.30.dfsg-3.12008-01-12
CVE-2007-6284 [MEDIUM] CVE-2007-6284: The xmlCurrentChar function in libxml2 before 2
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
osv
CVE-2009-2414P4MEDIUMCVSS 4.3v2.5.10v2.6.16+3 more2009-08-11
CVE-2009-2414 [MEDIUM] CWE-119 CVE-2009-2414: Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.
Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
nvdosv
CVE-2003-1564P4MEDIUMCVSS 6.5fixed in 2.5.02003-12-31
CVE-2003-1564 [MEDIUM] CWE-776 CVE-2003-1564: libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which al
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."
nvd
CVE-2026-0989P4LOWCVSS 3.7fixed in 2.15.22026-01-15
CVE-2026-0989 [LOW] CWE-674 CVE-2026-0989: A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating
nvdosv
CVE-2010-4008P4MEDIUMCVSS 4.3fixed in 2.7.82010-11-17
CVE-2010-4008 [MEDIUM] CWE-119 CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, an
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
nvdosv
CVE-2025-8732P4LOWCVSS 3.3fixed in 2.15.2v2.14.0+5 more2025-08-08
CVE-2025-8732 [LOW] CWE-404 CVE-2025-8732: A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnera
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vuln
nvdosv
CVE-2026-0992P4LOWCVSS 2.9fixed in 2.15.22026-01-15
CVE-2026-0992 [LOW] CWE-400 CVE-2026-0992: A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU c
nvdosv
CVE-2025-6170P4LOWCVSS 2.5≥ 0, < 2.9.10+dfsg-6.7+deb11u8≥ 0, < 2.9.14+dfsg-1.3~deb12u3+1 more2025-06-16
CVE-2025-6170 [LOW] CVE-2025-6170: A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
osv
CVE-2026-86141P4LOWCVSS 2.9fixed in 2.15.42026-09-05
CVE-2026-86141 [LOW] CWE-252 CVE-2026-86141: xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a str
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
nvd
CVE-2026-86137P4LOWCVSS 2.9fixed in 2.15.42026-09-05
CVE-2026-86137 [LOW] CWE-125 CVE-2026-86137: In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds rea
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
nvd
CVE-2025-12863UNKNOWN≥ 0, < 2.15.1+dfsg-0.42025-11-07
CVE-2025-12863 CVE-2025-12863: A flaw was found in the xmlSetTreeDoc() function of the libxml2 XML parsing library
A flaw was found in the xmlSetTreeDoc() function of the libxml2 XML parsing library. This function is responsible for updating document pointers when XML nodes are moved between documents. Due to improper handling of namespace references, a namespace pointer may remain linked to a freed memory region when the original document is destroyed. As a result, subsequent operations that ac
osv
← Previous7 / 7