CVE-2026-8177

EUVD-2026-29000
XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences.

A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory.

Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
perl-XML-LibXML
suse enterprise sap 15 SP4
2.0132-150000.3.8.1
fixed
suse enterprise sap 15 SP5
2.0132-150000.3.8.1
fixed
suse enterprise sap 15 SP6
2.0132-150000.3.8.1
fixed
suse enterprise server 12 SP5
2.0019-6.8.1
fixed
suse enterprise server 15 SP4
2.0132-150000.3.8.1
fixed
suse enterprise server 15 SP5
2.0132-150000.3.8.1
fixed
suse enterprise server 15 SP6
2.0132-150000.3.8.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-XML-LibXML
Amazon Linux 2
1:2.0018-5.amzn2.0.3
fixed
Amazon Linux 2023
1:2.0210-7.amzn2023.0.3
fixed
perl-XML-LibXML-debuginfo
Amazon Linux 2
1:2.0018-5.amzn2.0.3
fixed
Amazon Linux 2023
1:2.0210-7.amzn2023.0.3
fixed
perl-XML-LibXML-debugsource
Amazon Linux 2023
1:2.0210-7.amzn2023.0.3
fixed
perl-XML-LibXML-tests
Amazon Linux 2023
1:2.0210-7.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
perl-XML-LibXML
Azure Linux 3.0
0:2.0209-3.azl3
fixed