CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-6653

Critical · CVSS 9.8

libxml2 — Use After Free / XML External Entity (XXE) injection leading to Denial of Service

CVSS
9.8
nvd
EPSS
0.29%
21th pct
KEV
No
Class
oss containerizable
CWE-416, CWE-611

Description

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

Search profile — drives PoC discovery

Symbols xmlParseInternalSubsetxmlParseEntityDeclxmlParseEntityRefxmlParseAttValuexmlFreeDocxmlFreeParserxmlNewDocxmlCtxtReadMemoryXML_INTERNAL_SUBSET_NODExmlSAXHandlerentityDeclresolveEntityxmlParserCtxtxmlDocPtrxmlNodePtr
Keywords CVE-2026-6653libxml2 use-after-freelibxml2 xmlParseInternalSubsetlibxml2 entity resolution UAFlibxml2 DoS malformed XMLlibxml2 2.9.11 2.11.0 vulnerabilityCWE-416 libxml2CWE-611 libxml2 XXEGNOME libxml2 internal subset exploitlibxml2 xmlParseInternalSubset PoClibxml2 denial of service entity handling
Versions: 2.9.11 to 2.11.0

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-15T06:30:20.000Z