Back to overview

CVE-2026-6653

HIGH
7.0
CVSS 4.0
Description
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

Metadata

CVE ID
CVE-2026-6653
State
PUBLISHED
Assigner
canonical
Reserved
2026-04-20 06:37 UTC
Published
2026-06-22 12:40 UTC
Last updated
2026-06-22 15:51 UTC
Primary CWE
CWE-416
CWE-416 Use after free
Vendor / Product
GNOME / libxml2
Sources
cve.org  ·  NVD

Severity & Metrics

7.0 HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
GNOME libxml2 2.9.11 < 2.11.0
Weakness (CWE)
CWESourceDescription
CWE-416 cna CWE-416 Use after free
CWE-611 cna CWE-611 Improper Restriction of XML External Entity Processing
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.0 HIGH 4.0 cna CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Back to overview