Description
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 05 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | |
| First Time appeared |
Xmlsoft
Xmlsoft libxml2 |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xmlsoft
Xmlsoft libxml2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-05T04:23:14.686Z
Reserved: 2026-09-05T04:23:14.327Z
Link: CVE-2026-86139
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses