Xmlsoft
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Xmlsoft product.
RSS Feeds for Xmlsoft security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Xmlsoft products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Xmlsoft Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 9 vulnerabilities in Xmlsoft with an average score of 5.9 out of ten. Last year, in 2025 Xmlsoft had 9 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Xmlsoft in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.04
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 9 | 5.88 |
| 2025 | 9 | 5.91 |
| 2024 | 2 | 7.50 |
| 2023 | 5 | 6.93 |
| 2022 | 5 | 7.33 |
| 2021 | 6 | 7.73 |
| 2020 | 3 | 7.17 |
| 2019 | 5 | 7.08 |
| 2018 | 7 | 6.87 |
It may take a day or so for new Xmlsoft vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Xmlsoft Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-86144 | Sep 05, 2026 |
libxml2 <2.15.4 XInclude parseFlags not propagated XEE/SSRF riskIn xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow). |
|
| CVE-2026-86143 | Sep 05, 2026 |
libxml2 2.15.4 xmlIO Int Overflow via Negative LengthsIn xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback. |
|
| CVE-2026-86142 | Sep 05, 2026 |
Heap-Overflow in libxml2 <2.15.4 xmlXPtrEvalXPtrPartIn libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. |
|
| CVE-2026-86141 | Sep 05, 2026 |
NULL Ptr Deref in xmlRegNewParserCtxt via xmlregexp (libxml2 <2.15.4)xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking. |
|
| CVE-2026-86140 | Sep 05, 2026 |
libxml2 <2.15.4 Stack-Based Buffer Overflow in xmlSnprintfElementsIn libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. |
|
| CVE-2026-86139 | Sep 05, 2026 |
libxml2: xmlURIEscapeStr Integer Overflow before 2.15.4In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. |
|
| CVE-2026-86138 | Sep 05, 2026 |
libxml2 < 2.15.4: Integer Overflow in xmlDictAddQString (Heap BOverflow)In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. |
|
| CVE-2026-86137 | Sep 05, 2026 |
libxml2 <2.15.4 OOB Read in xmlFAParsePosCharGroup (xmlregexp NXT macro)In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. |
|
| CVE-2026-11979 | Jun 29, 2026 |
Stack Overflow in libxml2 xmlcatalog --shell modelibxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug. |
|
| CVE-2025-6170 | Jun 16, 2025 |
xmllint CLI Buffer Overflow via Oversized Input in Interactive ShellA flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections. |
|