CVE-2026-74860

Published: September 10, 2026Last modified: September 28, 2026

Description

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.

Severity score breakdown

ParameterValue
Base score8.5
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibxml2Unknown (2.10.3-r2)
25 LTSlibxml2Unknown (2.13.8-r0)
Streamlibxml2Fixed (2.13.9-r6)
Hardened Containers23 LTSlibxml2Unknown (2.10.3-r2)
25 LTSlibxml2Unknown (2.13.8-r0)
Streamlibxml2Unknown (2.10.3-r2)

References

ON THIS PAGE