Description
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
Published: 2026-09-08
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via double‑free in libxml2 Python bindings
Action: Apply Patch
AI Analysis

Impact

A flaw (CWE‑763) exists in libxml2 when Python bindings are enabled. A remote attacker can supply a crafted XML document that includes a DTD with enumerated attribute values. This causes the SAX attributeDecl callback to free a string twice, leading to a null pointer dereference and a crash. The result is a denial‑of‑service because the affected Python application will terminate.

Affected Systems

Red Hat’s Red Enterprise Linux 6, 7, 8, 9, and 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4 are affected when libxml2 with Python bindings is used.

Risk and Exploitability

The CVSS score of 8.5 marks this flaw as high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote: an attacker can send a malicious XML payload to a vulnerable Python program that uses libxml2 with the bindings enabled. Because the flaw leads only to a crash and not to arbitrary code execution, the primary risk is a denial of service to the affected service or application. However, repeated crashes could be leveraged in a larger denial‑of‑service campaign, especially in a managed platform environment such as OpenShift.

Generated by OpenCVE AI on September 8, 2026 at 13:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s libxml2 update that addresses the double‑free bug.
  • If a patch is yet available, disable the Python bindings for libxml2 in the application configuration.
  • Implement strict XML validation or block external DTD processing to avoid triggering the defect when parsing untrusted XML.

Generated by OpenCVE AI on September 8, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat cert Manager
CPEs cpe:/a:redhat:cert_manager:1.20::el9
Vendors & Products Redhat cert Manager
References

Thu, 24 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9::appstream
cpe:/o:redhat:enterprise_linux:9::baseos
References

Thu, 24 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8::appstream
cpe:/o:redhat:enterprise_linux:8::baseos
References

Thu, 24 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10.2
References

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat hardened Images
Redhat openshift Container Platform
Vendors & Products Redhat hardened Images
Redhat openshift Container Platform

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
Title Libxml2: double-free/uaf in libxml2 python bindings
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Weaknesses CWE-763
CPEs cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Cert Manager Enterprise Linux Hardened Images Hummingbird Openshift Openshift Container Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-28T14:06:31.657Z

Reserved: 2026-08-17T09:57:05.862Z

Link: CVE-2026-74860

cve-icon Vulnrichment

Updated: 2026-09-08T12:08:39.849Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T12:16:58.083

Modified: 2026-09-28T15:17:23.507

Link: CVE-2026-74860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:35:08Z

Weaknesses
  • CWE-763

    Release of Invalid Pointer or Reference