Description
libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1688 | libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution. |
Github GHSA |
GHSA-mg49-jqgw-gcj6 | libxmljs vulnerable to type confusion when parsing specially crafted XML |
References
History
Fri, 10 Oct 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:libxmljs_project:libxmljs:*:*:*:*:*:node.js:*:* |
Mon, 25 Nov 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libxmljs Project
Libxmljs Project libxmljs |
|
| CPEs | cpe:2.3:a:libxmljs_project:libxmljs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libxmljs Project
Libxmljs Project libxmljs |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: JFROG
Published:
Updated: 2024-11-25T12:54:47.608Z
Reserved: 2024-05-02T11:56:38.360Z
Link: CVE-2024-34392
Updated: 2024-08-02T02:51:11.369Z
Status : Analyzed
Published: 2024-05-02T19:15:06.333
Modified: 2025-10-10T18:19:30.443
Link: CVE-2024-34392
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA