6.5mediumMedium

CVE-2026-6732

Xmlsoft Libxml2

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

Exploitation status

  • Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.

What the metrics mean

  • It is reachable only from the same local or logical network.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
6.5 (v3.1)
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness
CWE-843
Assigned by
secalert@redhat.com

Dates

Published
2026-04-23
Last modified
2026-08-31
Sources
NVD

Affected products

  • Xmlsoft Libxml22.13.0 - 2.15.3
  • Redhat Hardened Imagesall versions
  • Redhat Jboss Core Servicesall versions
  • Redhat Openshift Container Platform4.0
  • Redhat Enterprise Linux6.0, 7.0, 8.0, 9.0, 10.0
  • Ibm Vios4.1.0 - 4.1.1.30, 4.1.2.0
  • Ibm Aix7.2.5 - 7.2.5.12, 7.3.2 - 7.3.3.3, 7.3.4

As listed in the NVD configuration data. Not a statement about your estate.

References