Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 05 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XInclude Parse Flags Not Propagated, Enabling XML External Entity, SSRF, or DoS in libxml2 |
Sat, 05 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow). | |
| First Time appeared |
Xmlsoft
Xmlsoft libxml2 |
|
| Weaknesses | CWE-669 | |
| CPEs | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xmlsoft
Xmlsoft libxml2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-05T04:34:43.972Z
Reserved: 2026-09-05T04:34:43.632Z
Link: CVE-2026-86144
No data.
Status : Received
Published: 2026-09-05T05:17:13.407
Modified: 2026-09-05T05:17:13.407
Link: CVE-2026-86144
No data.
OpenCVE Enrichment
Updated: 2026-09-05T05:30:17Z
-
CWE-669
Incorrect Resource Transfer Between Spheres