7
/ 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
Basic Information
ID
CVE-2026-6653
Source
canonical
Published
Jun 22, 2026 at 12:40
Affected Product
Vendor
GNOME
Product
libxml2
Version
2.9.11
Affected Versions
GNOME libxml2 2.9.11