← Vulnerability feed

Vulnerability record · CVE-2026-86138 · published 5 September 2026

CVE-2026-86138: Xmlsoft libxml2 integer overflow vulnerability

Xmlsoft · Libxml2

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

7.8 CVSS 3.1 High EPSS 0.13% · top 97.7% CWE-190 · Integer overflow
7.8CVSS 3.1 base score
0.13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
15 Sep 2026Last modified by NVD

Description

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-86138 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3529Xmlsoft libxml2 memory buffer overflow vulnerabilityHeap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a …EPSS 23%10.0CVE-2004-0989Xmlsoft libxml vulnerabilityMultiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code vi…EPSS 22%9.8CVE-2024-56171Xmlsoft libxml2 use after free vulnerabilitylibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. …EPSS 1.2%9.8CVE-2017-7375Xmlsoft libxml2 xml external entity (xxe) vulnerabilityA flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…EPSS 2.6%9.8CVE-2017-7376Xmlsoft libxml2 memory buffer overflow vulnerabilityBuffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.EPSS 23%9.8CVE-2017-16931Xmlsoft libxml2 memory buffer overflow vulnerabilityparser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the …EPSS 4.3%9.8CVE-2016-4658Apple iphone os memory buffer overflow vulnerabilityxpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does…EPSS 8.6%9.8CVE-2016-4448Hp icewall federation agent vulnerabilityFormat string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.EPSS 7.0%

Source: NIST National Vulnerability Database (record CVE-2026-86138), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.