CVE-2026-6653

EUVD-2026-38232
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 28.23%
Affected Products (NVD)
VendorProductVersion
xmlsoftlibxml2
2.9.11 ≤
𝑥
≤ 2.11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxml2
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
2.15.3+dfsg-1
fixed
sid
2.15.3+dfsg-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxml2
bionic
not-affected
focal
not-affected
jammy
Fixed 2.9.13+dfsg-1ubuntu0.12
released
noble
Fixed 2.9.14+dfsg-1.3ubuntu3.8
released
questing
not-affected
resolute
not-affected
trusty
not-affected
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libxml2
Amazon Linux 2
0:2.9.1-6.amzn2.5.25
fixed
Amazon Linux 2023
0:2.10.4-1.amzn2023.0.19
fixed
libxml2-debuginfo
Amazon Linux 2
0:2.9.1-6.amzn2.5.25
fixed
Amazon Linux 2023
0:2.10.4-1.amzn2023.0.19
fixed
libxml2-debugsource
Amazon Linux 2023
0:2.10.4-1.amzn2023.0.19
fixed
libxml2-devel
Amazon Linux 2
0:2.9.1-6.amzn2.5.25
fixed
Amazon Linux 2023
0:2.10.4-1.amzn2023.0.19
fixed
libxml2-python
Amazon Linux 2
0:2.9.1-6.amzn2.5.25
fixed
libxml2-static
Amazon Linux 2
0:2.9.1-6.amzn2.5.25
fixed
Amazon Linux 2023
0:2.10.4-1.amzn2023.0.19
fixed
python3-libxml2
Amazon Linux 2023
0:2.10.4-1.amzn2023.0.19
fixed
python3-libxml2-debuginfo
Amazon Linux 2023
0:2.10.4-1.amzn2023.0.19
fixed