LOW 2.9 NVD
CVE-2026-86137
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
References
- https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2
- https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4
- https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099
This low severity vulnerability with a CVSS score of 2.9 was published on 2026-09-05 via NVD.
vulnfeed aggregates 10185 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.