Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XInclude Parse Flags Not Propagated, Enabling XML External Entity, SSRF, or DoS in libxml2 | libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation. |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 05 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XInclude Parse Flags Not Propagated, Enabling XML External Entity, SSRF, or DoS in libxml2 |
Sat, 05 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow). | |
| First Time appeared |
Xmlsoft
Xmlsoft libxml2 |
|
| Weaknesses | CWE-669 | |
| CPEs | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xmlsoft
Xmlsoft libxml2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-08T13:04:51.845Z
Reserved: 2026-09-05T04:34:43.632Z
Link: CVE-2026-86144
Updated: 2026-09-08T13:04:47.388Z
Status : Awaiting Analysis
Published: 2026-09-05T05:17:13.407
Modified: 2026-09-08T21:14:09.040
Link: CVE-2026-86144
OpenCVE Enrichment
Updated: 2026-09-08T02:45:09Z