Bug 2528992 (CVE-2026-86144) - CVE-2026-86144 libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation.
Summary: CVE-2026-86144 libxml2: libxml2: Information disclosure, SSRF, or denial of s...
Keywords:
Status: NEW
Alias: CVE-2026-86144
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2529731 2529732 2529733 2529734
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-05 04:51 UTC by OSIDB Bzimport
Modified: 2026-09-08 11:07 UTC (History)
27 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-05 04:51:21 UTC
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).


Note You need to log in before you can comment on or make changes to this bug.