CVE-2026-6732

Published: April 24, 2026Last modified: April 25, 2026

Description

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibxml2Not affected (2.10.3-r2)
25 LTSlibxml2Vulnerable (2.13.8-r0)
Streamlibxml2Vulnerable (2.13.8-r0)
Hardened Containers23 LTSlibxml2Not affected (2.10.3-r2)
25 LTSlibxml2Vulnerable (2.13.8-r0)
Streamlibxml2Vulnerable (2.13.8-r0)

References

ON THIS PAGE