← Vulnerability feed

Vulnerability record · CVE-2026-6653 · published 22 June 2026

CVE-2026-6653: Xmlsoft libxml2 use after free vulnerability

Xmlsoft · Libxml2

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

7.0 CVSS 4.0 High EPSS 0.36% · top 73.3% CWE-416 · Use after freeCWE-611 · XML external entity (XXE)
7.0CVSS 4.0 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
14 Jul 2026Last modified by NVD

Description

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260 ExploitIssue TrackingThird Party Advisory
https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058 ExploitIssue TrackingPatch

Track CVE-2026-6653 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3529Xmlsoft libxml2 memory buffer overflow vulnerabilityHeap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a …EPSS 23%10.0CVE-2004-0989Xmlsoft libxml vulnerabilityMultiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code vi…EPSS 22%9.8CVE-2024-56171Xmlsoft libxml2 use after free vulnerabilitylibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. …EPSS 1.2%9.8CVE-2017-7375Xmlsoft libxml2 xml external entity (xxe) vulnerabilityA flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…EPSS 2.6%9.8CVE-2017-7376Xmlsoft libxml2 memory buffer overflow vulnerabilityBuffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.EPSS 23%9.8CVE-2017-16931Xmlsoft libxml2 memory buffer overflow vulnerabilityparser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the …EPSS 4.3%9.8CVE-2016-4658Apple iphone os memory buffer overflow vulnerabilityxpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does…EPSS 8.6%9.8CVE-2016-4448Hp icewall federation agent vulnerabilityFormat string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.EPSS 7.0%

Source: NIST National Vulnerability Database (record CVE-2026-6653), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.