← Browse

CVE-2026-86144

Low

No strong exploitation signal.

CVSS base
5.6 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS — probability of exploitation (30 days)
0.2%
7.5th percentile
CISA KEV
Not listed
Weakness / dates
CWE-669
Published 2026-09-05 · modified 2026-09-15

CVSS breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

Attack VectorLLocal
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionNNone
ScopeCChanged
ConfidentialityLLow
IntegrityLLow
AvailabilityLLow

Timeline

Description

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

Affected

xmlsoft

References

Official: NVD · CVE.org