{"id":"ECHO-778a-550a-1fd5","summary":"Type confusion in xmlParseReference (ctxt vs ctxt-\u003euserData in SAX\ncallbacks). Introduced by commit e1153832 (\"parser: Fix quadratic\nbehavior when copying entities\", 2024-01-07), first released in\nv2.13.0. Last unaffected release: v2.12.10. Debian trixie package\nis 2.12.7+dfsg+really2.9.14 (effectively v2.9.14) which predates\nthe bug — all SAX callbacks in xmlParseReference already correctly\npass ctxt-\u003euserData. Verified against the actual Debian source from\nsalsa.debian.org. Not exploitable.\n","modified":"2026-09-15T00:47:46.195087464Z","published":"2026-05-07T18:28:28.441323Z","withdrawn":"2026-05-06T18:45:01.114Z","upstream":["CVE-2026-6732"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-6732"}],"affected":[{"package":{"name":"libxml2","ecosystem":"Echo","purl":"pkg:deb/echo/libxml2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12.7+dfsg+really2.9.14-2.1+deb13u2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-778a-550a-1fd5.json"}}],"schema_version":"1.9.0"}