📦 Libxml2

by Xmlsoft

🔍 What is Libxml2?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-40896

CRITICAL CVSS 9.1 Dec 23, 2024

This vulnerability in libxml2 allows attackers to bypass custom SAX handler protections against external entity processing, enabling classic XML External Entity (XXE) attacks. Any application using af...

CVE-2025-6021

HIGH CVSS 7.5 Jun 12, 2025

This CVE describes an integer overflow vulnerability in libxml2's xmlBuildQName function that can cause stack-based buffer overflow when processing malicious XML input. This vulnerability affects any ...

CVE-2025-24928

HIGH CVSS 7.8 Feb 18, 2025

This CVE describes a stack-based buffer overflow vulnerability in libxml2's xmlSnprintfElements function. Attackers can exploit this by providing malicious XML documents with DTD validation enabled, p...

CVE-2022-49043

HIGH CVSS 8.1 Jan 26, 2025

CVE-2022-49043 is a use-after-free vulnerability in libxml2's xmlXIncludeAddNode function that allows attackers to execute arbitrary code or cause denial of service. This affects any application that ...

CVE-2024-34459

HIGH CVSS 7.5 May 14, 2024

This vulnerability in xmllint (part of libxml2) allows attackers to trigger a buffer over-read when formatting error messages with the --htmlout flag. This could lead to information disclosure or appl...

CVE-2024-25062

HIGH CVSS 7.5 Feb 4, 2024

A use-after-free vulnerability in libxml2's XML Reader interface when processing crafted XML documents with DTD validation and XInclude expansion enabled. This affects applications using vulnerable li...

CVE-2022-23308

HIGH CVSS 7.5 Feb 26, 2022

CVE-2022-23308 is a use-after-free vulnerability in libxml2's validation component that allows attackers to potentially execute arbitrary code or cause denial of service. It affects applications that ...

CVE-2021-3518

HIGH CVSS 8.8 May 18, 2021

A use-after-free vulnerability in libxml2 versions before 2.9.11 allows attackers to submit crafted XML files to applications using this library, potentially leading to arbitrary code execution. This ...

CVE-2025-9714

MEDIUM CVSS 6.2 Sep 10, 2025

This vulnerability allows a local attacker to cause a stack overflow via crafted XPath expressions in libxml2. It affects applications using libxml2 for XML/XPath processing, potentially leading to de...