CVE-2026-86137 | xmlsoft libxml2 up to 2.15.3 NXT macro xmlFAParsePosCharGroup out-of-bounds
A vulnerability marked as critical has been reported in xmlsoft libxml2 up to 2.15.3. The affected element is the function xmlFAParsePosCharGroup of the component NXT macro. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-86137. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More