CVE-2026-86143: Schwachstellen-Eintrag (NVD)
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-05 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-86143 | xmlsoft libxml2 up to 2.15.3 xmlIO xmlOutputWriteCallback integer overflow (Nessus ID 343104)
A vulnerability classified as problematic was found in xmlsoft libxml2 up to 2.15.3. This impacts the function xmlOutputWriteCallback of the component xmlIO. The manipulation results in integer overflow. This vulnerability is known as CVE-2