High severity8.1NVD Advisory· Published May 2, 2024· Updated Apr 15, 2026
CVE-2024-34394
CVE-2024-34394
Description
libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
libxmljs2npm | <= 0.35.0 | — |
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-78h3-pg4x-j8cvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-34394ghsaADVISORY
- github.com/marudor/libxmljs2/issues/205nvdWEB
- research.jfrog.com/vulnerabilities/libxmljs2-namespaces-type-confusion-rce-jfsa-2024-001034098ghsaWEB
- research.jfrog.com/vulnerabilities/libxmljs2-namespaces-type-confusion-rce-jfsa-2024-001034098/nvd
News mentions
0No linked articles in our index yet.