CVE-2026-86144
Last modified
CVE-2026-86144 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| xmlsoft | libxml2 | < 2.15.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-86144?
How severe is CVE-2026-86144?
How do I fix CVE-2026-86144?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86139In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an in…6.9
- CVE-2026-8614The Assistio plugin for WordPress is vulnerable to unauthori…4.3
- CVE-2026-86140In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has…8
- CVE-2026-86141xmlregexp in libxml2 before 2.15.4 has a NULL pointer derefe…2.9
- CVE-2026-86142In libxml2 before 2.15.4, there is a heap-based buffer overf…6.9
- CVE-2026-86143In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOu…6.9
- CVE-2026-86145PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds wr…8.2
- CVE-2026-86148A security flaw has been discovered in Tenda CP3 27.5.57.101…9.1
- CVE-2026-86149A weakness has been identified in Tenda CP3 27.5.57.101. Thi…9.1
- CVE-2026-86150A security vulnerability has been detected in Tenda CP3 27.5…4.1
- CVE-2026-86151A vulnerability was detected in Tenda CP3 27.5.57.101. The a…9.1
- CVE-2026-86152A flaw has been found in Tenda CP3 27.5.57.101. The impacted…10
Are you affected by CVE-2026-86144?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
