Xmlsoft Xmlsoft

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Xmlsoft product.

RSS Feeds for Xmlsoft security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Xmlsoft products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Xmlsoft Sorted by Most Security Vulnerabilities since 2018

Xmlsoft Libxml269 vulnerabilities

Xmlsoft Libxslt11 vulnerabilities

Xmlsoft Libxml2 vulnerabilities

Xmlsoft Xmllint2 vulnerabilities

By the Year

In 2026 there have been 9 vulnerabilities in Xmlsoft with an average score of 5.9 out of ten. Last year, in 2025 Xmlsoft had 9 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Xmlsoft in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.04




Year Vulnerabilities Average Score
2026 9 5.88
2025 9 5.91
2024 2 7.50
2023 5 6.93
2022 5 7.33
2021 6 7.73
2020 3 7.17
2019 5 7.08
2018 7 6.87

It may take a day or so for new Xmlsoft vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Xmlsoft Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-86144 Sep 05, 2026
libxml2 <2.15.4 XInclude parseFlags not propagated XEE/SSRF risk In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).
Libxml2
CVE-2026-86143 Sep 05, 2026
libxml2 2.15.4 xmlIO Int Overflow via Negative Lengths In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Libxml2
CVE-2026-86142 Sep 05, 2026
Heap-Overflow in libxml2 <2.15.4 xmlXPtrEvalXPtrPart In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
Libxml2
CVE-2026-86141 Sep 05, 2026
NULL Ptr Deref in xmlRegNewParserCtxt via xmlregexp (libxml2 <2.15.4) xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
Libxml2
CVE-2026-86140 Sep 05, 2026
libxml2 <2.15.4 Stack-Based Buffer Overflow in xmlSnprintfElements In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
Libxml2
CVE-2026-86139 Sep 05, 2026
libxml2: xmlURIEscapeStr Integer Overflow before 2.15.4 In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
Libxml2
CVE-2026-86138 Sep 05, 2026
libxml2 < 2.15.4: Integer Overflow in xmlDictAddQString (Heap BOverflow) In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Libxml2
CVE-2026-86137 Sep 05, 2026
libxml2 <2.15.4 OOB Read in xmlFAParsePosCharGroup (xmlregexp NXT macro) In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
Libxml2
CVE-2026-11979 Jun 29, 2026
Stack Overflow in libxml2 xmlcatalog --shell mode libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.
Libxml2
CVE-2025-6170 Jun 16, 2025
xmllint CLI Buffer Overflow via Oversized Input in Interactive Shell A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Libxml2
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.