VYPR
Medium severity6.9NVD Advisory· Published Sep 5, 2026· Updated Sep 8, 2026

CVE-2026-86143

CVE-2026-86143

Description

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.