---
id: CVE-2026-8177
title: >-
  XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory
  when parsing XML node names containing truncated UTF-8 byte sequences.


  A node name ending in the middle of a multi byte UTF-8 sequence causes the
  parser to read…
summary: >-
  XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory
  when parsing XML node names containing truncated UTF-8 byte sequences.


  A node name ending in the middle of a multi byte UTF-8 sequence causes the
  parser to read…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
vendor: Red Hat
product: Red Hat Enterprise Linux AppStream (v. 10)
affected:
  - enterprise_linux 6
  - enterprise_linux 7
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_v_9
patched:
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_v_9
published: '2026-05-10'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:18:37.633'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8177'
references:
  - url: >-
      https://github.com/cpan-authors/XML-LibXML/commit/15652bd905a6c9dda59a81b14d4766adbbae2ea8.patch
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'https://github.com/cpan-authors/XML-LibXML/issues/146'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'https://github.com/cpan-authors/XML-LibXML/pull/149'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/10/8'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/11/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:39547'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:39553'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:39878'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:68632'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:68685'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:68688'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:68693'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-8177'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2468684'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8177.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-8177'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8177'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00882
epssPercentile: 0.57505
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-05-11T16:34:46.706997Z'
ingestedAt: '2026-07-16T02:48:54.904Z'
---

## Overview

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences.

A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory.

Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:68632** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68632)
- **RHSA-2026:39547** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:39547)
- **RHSA-2026:39878** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:39878)
- **RHSA-2026:68688** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68688)
- **RHSA-2026:39553** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-07-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:39553)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8177.json)
- **RHSA-2026:68685** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68685)
- **RHSA-2026:68693** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68693)
