Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 05 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Integer Overflow in libxml2 Output Callbacks |
Sat, 05 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback. | |
| First Time appeared |
Xmlsoft
Xmlsoft libxml2 |
|
| Weaknesses | CWE-192 | |
| CPEs | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xmlsoft
Xmlsoft libxml2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-05T04:31:21.187Z
Reserved: 2026-09-05T04:31:20.849Z
Link: CVE-2026-86143
No data.
Status : Received
Published: 2026-09-05T05:17:13.270
Modified: 2026-09-05T05:17:13.270
Link: CVE-2026-86143
No data.
OpenCVE Enrichment
Updated: 2026-09-05T06:30:04Z