{"id":"CVE-2026-6653","summary":"libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling","details":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.","modified":"2026-08-31T14:56:40.186381967Z","published":"2026-06-22T12:40:31.424Z","related":["ALSA-2026:61247"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6653.json","cna_assigner":"canonical","cwe_ids":["CWE-416","CWE-611"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6653.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6653"},{"type":"REPORT","url":"https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"},{"type":"PACKAGE","url":"https://gitlab.gnome.org/GNOME/libxml2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/libxml2","events":[{"introduced":"e1bcffea180d6cc0651757bb64284a763e0e2239"},{"last_affected":"f296934ade688baab79caf1c62a82149ad78accf"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.9.11"},{"last_affected":"2.11.0"}]}},{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/libxml2","events":[{"introduced":"e1bcffea180d6cc0651757bb64284a763e0e2239"},{"fixed":"f296934ade688baab79caf1c62a82149ad78accf"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.9.11"},{"fixed":"2.11.0"},{"last_affected":"2.11.0"}]}}],"versions":["v2.11.0","v2.10.0","v2.9.13","v2.9.12","v2.9.11"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-6653.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}