Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Read in libxml2's xmlFAParsePosCharGroup | libxml2: libxml2: Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 05 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Read in libxml2's xmlFAParsePosCharGroup |
Sat, 05 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. | |
| First Time appeared |
Xmlsoft
Xmlsoft libxml2 |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xmlsoft
Xmlsoft libxml2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-14T13:50:50.073Z
Reserved: 2026-09-05T04:19:30.345Z
Link: CVE-2026-86137
Updated: 2026-09-14T13:48:09.247Z
Status : Analyzed
Published: 2026-09-05T05:17:11.490
Modified: 2026-09-15T19:46:11.827
Link: CVE-2026-86137
OpenCVE Enrichment
Updated: 2026-09-05T06:00:12Z