Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Read in libxml2's xmlFAParsePosCharGroup | libxml2: libxml2: Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 05 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Read in libxml2's xmlFAParsePosCharGroup |
Sat, 05 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. | |
| First Time appeared |
Xmlsoft
Xmlsoft libxml2 |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xmlsoft
Xmlsoft libxml2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-05T04:19:30.745Z
Reserved: 2026-09-05T04:19:30.345Z
Link: CVE-2026-86137
No data.
Status : Awaiting Analysis
Published: 2026-09-05T05:17:11.490
Modified: 2026-09-08T21:14:09.040
Link: CVE-2026-86137
OpenCVE Enrichment
Updated: 2026-09-05T06:00:12Z