Vulnerability Description
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xmlsoft | Libxml2 | < 2.15.4 |
Related Weaknesses (CWE)
References
- https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35Patch
- https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4Release Notes
- https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111ExploitVendor Advisory
FAQ
What is CVE-2026-86143?
CVE-2026-86143 is a vulnerability with a CVSS score of 6.9 (MEDIUM). In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling ...
How severe is CVE-2026-86143?
CVE-2026-86143 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-86143?
Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxml2.