{"id":"ROOT-OS-DEBIAN-13-CVE-2026-86140","summary":"CVE-2026-86140 in libxml2 - Patched by Root","details":"Root has patched CVE-2026-86140 in the libxml2 package for Root:Debian:13. Multiple fixed versions available.","modified":"2026-09-21T09:15:02.836503654Z","published":"2026-09-21T08:07:03Z","upstream":["CVE-2026-86140"],"database_specific":{"severity":"HIGH","source":"Root","distro":"debian","distro_version":"13"},"affected":[{"package":{"name":"libxml2","ecosystem":"Root:Debian:13"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12.7+dfsg+really2.9.14-2.1+deb13u3.aikido.15"},{"fixed":"2.12.7+dfsg+really2.9.14-2.1+deb13u3.aikido.16"}]}],"database_specific":{"all_fixed_versions":["2.12.7+dfsg+really2.9.14-2.1+deb13u3.aikido.15","2.12.7+dfsg+really2.9.14-2.1+deb13u3.aikido.16"],"root_patch_version":"aikido.16","root_patched":true,"source":"https://api.root.io/external/osv/ROOT-OS-DEBIAN-13-CVE-2026-86140.json","total_fixed_versions":2,"upstream_version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"}},{"package":{"name":"rootio-libxml2","ecosystem":"Root:Debian:13"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12.7+dfsg+really2.9.14-2.1+deb13u3.aikido.15"},{"fixed":"2.12.7+dfsg+really2.9.14-2.1+deb13u3.aikido.16"}]}],"database_specific":{"root_patch_version":"aikido.16","root_patched":true,"total_fixed_versions":2,"upstream_version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","all_fixed_versions":["2.12.7+dfsg+really2.9.14-2.1+deb13u3.aikido.15","2.12.7+dfsg+really2.9.14-2.1+deb13u3.aikido.16"],"source":"https://api.root.io/external/osv/ROOT-OS-DEBIAN-13-CVE-2026-86140.json"}}],"schema_version":"1.9.0"}