Search CVE reports


Toggle filters

1 – 10 of 133 results


CVE-2026-0992

Medium priority
Needs evaluation

A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-0990

Medium priority
Needs evaluation

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-0989

Medium priority
Needs evaluation

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-12863

Medium priority
Not affected

Rejected reason: This CVE was assigned for a libxml2 issue#1012 but later deemed not valid. Ref.: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1012#note_2608283

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-26434

Medium priority
Not affected

In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-9714

Medium priority
Fixed

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-8732

Low priority
Needs evaluation

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-7425

Medium priority

Some fixes available 7 of 16

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents...

2 affected packages

libxslt, libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxslt Vulnerable Vulnerable Vulnerable Vulnerable
libxml2 Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-6170

Medium priority

Some fixes available 7 of 8

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash....

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-49796

Medium priority

Some fixes available 7 of 8

A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Fixed Fixed Fixed Fixed
Show less packages