CVE-2026-6732 Details
Description
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.
A denial-of-service vulnerability has been identified in libxml2. The issue arises when the library processes XML documents validated by XML Schema Definitions (XSD) that contain internal entity references. This flaw creates a type confusion error, causing applications to crash and making systems unavailable. The vulnerability can be exploited by providing a maliciously crafted document that takes advantage of this flaw during entity expansion, particularly when streaming XSD validation is active.
Users can update to the latest version of libxml2, where this vulnerability has been fixed. Red Hat users should refer to the Red Hat Update Management documentation for guidance on applying the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:11503 | [email protected] | Third Party Advisory |
| https://access.redhat.com/security/cve/CVE-2026-6732 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2461300 | [email protected] | Issue TrackingThird Party Advisory |
| https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411 | [email protected] | Issue TrackingThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xmlsoft libxml2 | >= 2.13.0, < 2.15.3 |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat jboss core services | All versions |
CPE
Remediation
| |
| redhat openshift container platform | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
| ibm vios | >= 4.1.0, < 4.1.1.30 4.1.2.0 |
CPE
Remediation
| |
| ibm aix | >= 7.2.5, < 7.2.5.12 >= 7.3.2, < 7.3.3.3 7.3.4 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | Modified Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 15, 2026 | Reanalysis | [email protected] |
| May 5, 2026 | Initial Analysis | [email protected] |
| Apr 30, 2026 | CVE Modified | [email protected] |
| Apr 23, 2026 | New CVE Received | [email protected] |