CVE-2026-6653
Critical · CVSS 9.8libxml2 — Use After Free / XML External Entity (XXE) injection leading to Denial of Service
- CVSS
- 9.8
- nvd
- EPSS
- 0.29%
- 21th pct
- KEV
- No
- Class
- oss containerizable
- CWE-416, CWE-611
Description
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
Search profile — drives PoC discovery
Symbols xmlParseInternalSubsetxmlParseEntityDeclxmlParseEntityRefxmlParseAttValuexmlFreeDocxmlFreeParserxmlNewDocxmlCtxtReadMemoryXML_INTERNAL_SUBSET_NODExmlSAXHandlerentityDeclresolveEntityxmlParserCtxtxmlDocPtrxmlNodePtr
Keywords CVE-2026-6653libxml2 use-after-freelibxml2 xmlParseInternalSubsetlibxml2 entity resolution UAFlibxml2 DoS malformed XMLlibxml2 2.9.11 2.11.0 vulnerabilityCWE-416 libxml2CWE-611 libxml2 XXEGNOME libxml2 internal subset exploitlibxml2 xmlParseInternalSubset PoClibxml2 denial of service entity handling
Versions: 2.9.11 to 2.11.0
References
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-15T06:30:20.000Z