Medium severity6.9NVD Advisory· Published Sep 5, 2026· Updated Sep 8, 2026
CVE-2026-86143
CVE-2026-86143
Description
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Affected products
1- Range: <2.15.4
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.