CVE-2026-86143
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
- EPSS probability
- 0.12%
- CWE
- CWE-192
- Published
- 2026-09-05
- Last modified
- 2026-09-08
Affected products
- xmlsoft libxml2
Weakness type
Related vulnerabilities
- CVE-2026-8276 — bettercap MySQL Server mysql_server.go integer coercion
- CVE-2026-8275 — bettercap zerogod IPP Service zerogod_ipp_primitives.go ippReadChunkedBody integer coercion
- CVE-2022-2639 — An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large...
- CVE-2014-125012 — FFmpeg dxtroy.c integer coercion
- CVE-2014-125011 — FFmpeg ansi.c decode_frame integer coercion
- CVE-2021-32996 — The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which...