VulnSea

xmlsoft has 11 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 8 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 8. The median CVSS is 6.9 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-190 (3). Most affected products: libxml2 (10), libxslt (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.9
Publish → KEV
Last 90 days
8 prev 1

Products

  • libxml2 10
  • libxslt 1
11
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

xmlsoft vulnerabilities

CVEs affecting xmlsoft, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-86144Medium· 5.6
2w ago

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses th…

Sunlitxmlsoft · libxml2EPSS 0.18%via NVD
CVE-2026-86143Medium· 6.9
2w ago

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security rele…

Sunlitxmlsoft · libxml2EPSS 0.13%via NVD
CVE-2026-86142Medium· 6.9
2w ago

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

Sunlitxmlsoft · libxml2EPSS 0.15%via NVD
CVE-2026-86141Low· 2.9
2w ago

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

Sunlitxmlsoft · libxml2EPSS 0.12%via NVD
CVE-2026-86140High· 8.0
2w ago

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

Twilightxmlsoft · libxml2EPSS 0.15%via NVD
CVE-2026-86139Medium· 6.9
2w ago

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

Sunlitxmlsoft · libxml2EPSS 0.11%via NVD
CVE-2026-86138Medium· 6.9
2w ago

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

Sunlitxmlsoft · libxml2EPSS 0.13%via NVD
CVE-2026-86137Low· 2.9
2w ago

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

Sunlitxmlsoft · libxml2EPSS 0.13%via NVD
CVE-2026-6732Medium· 6.5
5mo ago

A flaw was found in libxml2

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing …

Sunlitxmlsoft · libxml2EPSS 0.63%via NVD
CVE-2025-7424High· 7.5
1y ago

A flaw was found in the libxslt library

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application…

Twilightxmlsoft · libxsltEPSS 1.2%via NVD
CVE-2025-6021High· 7.5PoC
1y ago

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafte…

Midnightxmlsoft · libxml2EPSS 1.4%via NVD
xmlsoft vulnerabilities (CVEs) · VulnSea