In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap-Based Buffer Overflow in libxml2 via XPointer Evaluation |
Sat, 05 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. | |
| First Time appeared |
Xmlsoft
Xmlsoft libxml2 |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xmlsoft
Xmlsoft libxml2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-05T04:29:33.323Z
Reserved: 2026-09-05T04:29:32.967Z
Link: CVE-2026-86142
No data.
Status : Received
Published: 2026-09-05T05:17:13.133
Modified: 2026-09-05T05:17:13.133
Link: CVE-2026-86142
No data.
OpenCVE Enrichment
Updated: 2026-09-05T06:30:04Z
Weaknesses