Vulnerability Description
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xmlsoft | Libxml2 | >= 2.9.11, <= 2.11.0 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260ExploitIssue TrackingThird Party Advisory
- https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058ExploitIssue TrackingPatch
FAQ
What is CVE-2026-6653?
CVE-2026-6653 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper ent...
How severe is CVE-2026-6653?
CVE-2026-6653 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-6653?
Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxml2.