← Vulnerability feed

Vulnerability record · CVE-2024-34391 · published 2 May 2024

CVE-2024-34391: Libxmljs project libxmljs type confusion vulnerability

LLibxmljs Project · Libxmljs

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data leak, infinite loop and remote code execution (on 32-bit systems with the XML_PARSE_HUGE flag enabled).

9.8 CVSS 3.1 Critical EPSS 1.1% · top 35.6% CWE-843 · Type confusion
9.8CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data leak, infinite loop and remote code execution (on 32-bit systems with the XML_PARSE_HUGE flag enabled).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-34391 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-34392Libxmljs project libxmljs type confusion vulnerabilitylibxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes…EPSS 1.1%7.5CVE-2025-25341Libxmljs project libxmljs uncontrolled resource consumption vulnerabilityA vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and e…EPSS 0.42%7.5CVE-2022-21144Libxmljs project libxmljs improper input validation vulnerabilityThis affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invok…EPSS 1.9%8.8CVE-2026-85046Google Chrome V8 type confusion enables sandboxed remote code executionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) fixed in version 152.0.7977.82. A crafted HTML page can trigger the confusion …KEVEPSS 49%analysed7.8CVE-2026-21519Windows Desktop Window Manager type confusion privilege escalationThe Windows Desktop Window Manager (DWM) mishandles a resource using an incompatible type, a type confusion (CWE-843). A local attacker who already h…KEVEPSS 2.5%analysed8.8CVE-2025-13223Google Chrome V8 type confusion allows heap corruptionGoogle Chrome before 142.0.7444.175 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and pot…KEVEPSS 5.0%analysed9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed8.1CVE-2025-6554Google Chrome V8 type confusion enables arbitrary read/writeChrome before 138.0.7204.96 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the bug, letting an attacker …KEVEPSS 13%analysed

Source: NIST National Vulnerability Database (record CVE-2024-34391), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.