Heap-based buffer overflow in Libxml2 - CVE-2026-86142
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in xmlXPtrEvalXPtrPart when processing XPointer input. A remote attacker can provide crafted XPointer input to cause a denial of service.
The overflow is caused by XPointer length saturation in xmlXPtrEval.