← Vulnerability feed

Vulnerability record · CVE-2026-11979 · published 29 June 2026

CVE-2026-11979: Xmlsoft libxml2 stack-based buffer overflow vulnerability

Xmlsoft · Libxml2

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.

1.8 CVSS 4.0 Low EPSS 0.15% · top 96.6% CWE-121 · Stack-based buffer overflow
1.8CVSS 4.0 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
30 Jun 2026Last modified by NVD

Description

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-11979 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3529Xmlsoft libxml2 memory buffer overflow vulnerabilityHeap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a …EPSS 23%10.0CVE-2004-0989Xmlsoft libxml vulnerabilityMultiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code vi…EPSS 22%9.8CVE-2024-56171Xmlsoft libxml2 use after free vulnerabilitylibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. …EPSS 1.2%9.8CVE-2017-7375Xmlsoft libxml2 xml external entity (xxe) vulnerabilityA flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…EPSS 2.6%9.8CVE-2017-7376Xmlsoft libxml2 memory buffer overflow vulnerabilityBuffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.EPSS 23%9.8CVE-2017-16931Xmlsoft libxml2 memory buffer overflow vulnerabilityparser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the …EPSS 4.3%9.8CVE-2016-4658Apple iphone os memory buffer overflow vulnerabilityxpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does…EPSS 8.6%9.8CVE-2016-4448Hp icewall federation agent vulnerabilityFormat string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.EPSS 7.0%

Source: NIST National Vulnerability Database (record CVE-2026-11979), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.