6.5mediumMedium
CVE-2026-6732
Xmlsoft Libxml2
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.
Exploitation status
- Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
What the metrics mean
- It is reachable only from the same local or logical network.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 6.5 (v3.1)
- Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Weakness
- CWE-843
- Assigned by
- secalert@redhat.com
Dates
- Published
- 2026-04-23
- Last modified
- 2026-08-31
- Sources
- NVD
Affected products
- Xmlsoft Libxml22.13.0 - 2.15.3
- Redhat Hardened Imagesall versions
- Redhat Jboss Core Servicesall versions
- Redhat Openshift Container Platform4.0
- Redhat Enterprise Linux6.0, 7.0, 8.0, 9.0, 10.0
- Ibm Vios4.1.0 - 4.1.1.30, 4.1.2.0
- Ibm Aix7.2.5 - 7.2.5.12, 7.3.2 - 7.3.3.3, 7.3.4
As listed in the NVD configuration data. Not a statement about your estate.