CVE-2026-86144CWE-669

CVE-2026-86144

Medium · published September 5, 2026

CVSS v3.1
5.6
EPSS
0%
Percentile
5.6
In the wild
Unconfirmed
What it is

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

The record
Technical detail
CVSS v3.1
5.6 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00161 · 5.6th percentile
Weakness
CWE-669 · Incorrect Resource Transfer Between Spheres
Published
2026-09-05T09:17Z
References (2)
EPSS history
Timeline
  • 06 SEP 03:33Z
    EPSS moved — → 0%
    epss
  • 05 SEP 04:34Z
    In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags
    cvelistv5