| CVE-2026-86144 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86143 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- Low
| — |
| CVE-2026-86142 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86141 | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- None
AAvailability- Low
| — |
| CVE-2026-86140 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86139 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86138 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86137 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- None
AAvailability- Low
| — |