GHSA-2j5r-8qjf-mq34MediumCVSS 5.5

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML...

Published
September 17, 2026
Last Modified
September 21, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a nextCatalog element lacks its mandatory catalog attribute, leading to the application crashing and causing a Denial of Service (DoS).

🔗 References (7)