In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XInclude Parse Flags Not Propagated, Enabling XML External Entity, SSRF, or DoS in libxml2 |
Sat, 05 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow). | |
| First Time appeared |
Xmlsoft
Xmlsoft libxml2 |
|
| Weaknesses | CWE-669 | |
| CPEs | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xmlsoft
Xmlsoft libxml2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-05T04:34:43.972Z
Reserved: 2026-09-05T04:34:43.632Z
Link: CVE-2026-86144
No data.
Status : Received
Published: 2026-09-05T05:17:13.407
Modified: 2026-09-05T05:17:13.407
Link: CVE-2026-86144
No data.
OpenCVE Enrichment
Updated: 2026-09-05T05:30:17Z
Weaknesses