CVE-2026-86141CWE-252

CVE-2026-86141

Low · published September 5, 2026

CVSS v3.1
2.9
EPSS
0%
Percentile
1.8
In the wild
Unconfirmed
What it is

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

The record
Technical detail
CVSS v3.1
2.9 · LOW
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00116 · 1.8th percentile
Weakness
CWE-252 · Unchecked Return Value
Published
2026-09-05T09:17Z
References (3)
EPSS history
Timeline
  • 06 SEP 03:33Z
    EPSS moved — → 0%
    epss
  • 05 SEP 04:27Z
    xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length…
    cvelistv5