In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Integer Overflow in libxml2 URI Escaping Function |
Sat, 05 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | |
| First Time appeared |
Xmlsoft
Xmlsoft libxml2 |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xmlsoft
Xmlsoft libxml2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-05T04:23:14.686Z
Reserved: 2026-09-05T04:23:14.327Z
Link: CVE-2026-86139
No data.
Status : Received
Published: 2026-09-05T05:17:12.730
Modified: 2026-09-05T05:17:12.730
Link: CVE-2026-86139
No data.
OpenCVE Enrichment
Updated: 2026-09-05T08:00:05Z
Weaknesses