ast_xml_open of the file xml.c. The manipulation results in xml external entity reference.This vulnerability was named CVE-2026-23739. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.