{"id":"ROOT-OS-DEBIAN-12-CVE-2026-0990","summary":"CVE-2026-0990 in rootio-libxml2 - Patched by Root","details":"Root has patched CVE-2026-0990 in the rootio-libxml2 package for Root:Debian:12. Multiple fixed versions available.","modified":"2026-07-21T14:00:19.575625147Z","published":"2026-04-29T12:57:28Z","withdrawn":"2026-07-21T14:00:19.575625025Z","upstream":["CVE-2026-0990"],"database_specific":{"severity":"MEDIUM","source":"Root","distro":"debian","distro_version":"12"},"affected":[{"package":{"name":"rootio-libxml2","ecosystem":"Root:Debian:12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.14+dfsg-1.3~deb12u5.root.io.11"},{"fixed":"2.9.14+dfsg-1.3~deb12u5.root.io.13"},{"fixed":"2.9.14+dfsg-1.3~deb12u5.root.io.1"},{"fixed":"2.9.14+dfsg-1.3~deb12u5.root.io.9"},{"fixed":"2.9.14+dfsg-1.3~deb12u5.root.io.10"},{"fixed":"2.9.14+dfsg-1.3~deb12u5.root.io.12"},{"fixed":"2.9.14+dfsg-1.3~deb12u5.root.io.14"},{"fixed":"2.9.14+dfsg-1.3~deb12u5.root.io.15"}]}],"database_specific":{"root_patch_version":"root.io.15","root_patched":true,"total_fixed_versions":8,"upstream_version":"2.9.14+dfsg-1.3~deb12u5","all_fixed_versions":["2.9.14+dfsg-1.3~deb12u5.root.io.11","2.9.14+dfsg-1.3~deb12u5.root.io.13","2.9.14+dfsg-1.3~deb12u5.root.io.1","2.9.14+dfsg-1.3~deb12u5.root.io.9","2.9.14+dfsg-1.3~deb12u5.root.io.10","2.9.14+dfsg-1.3~deb12u5.root.io.12","2.9.14+dfsg-1.3~deb12u5.root.io.14","2.9.14+dfsg-1.3~deb12u5.root.io.15"],"source":"https://api.root.io/external/osv/ROOT-OS-DEBIAN-12-CVE-2026-0990.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}