CVE-2026-86144 | xmlsoft libxml2 up to 2.15.3 xinclude xmlXIncludeProcess parseFlags xml external entity reference

SecurityVulns

A vulnerability classified as critical has been found in xmlsoft libxml2 up to 2.15.3. This affects the function xmlXIncludeProcess of the component xinclude. The manipulation of the argument parseFlags leads to xml external entity reference.

This vulnerability is traded as CVE-2026-86144. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More