Junglewise Threat Intelligence

CVE-2026-74860: libxml2 double-free in SAX DTD attribute parsing

CVE-2026-74860 · Severity: high · CVSS 8.5 · Published 2026-09-08

Technologies: libxml2 Project Libxml2.

Executive brief

libxml2 is a widely-used library for parsing and manipulating XML documents, with Python bindings in many applications. A flaw in the SAX parser allows an attacker to send a specially crafted XML file with malicious DTD definitions, causing the library to crash when processing it. This can disrupt services that rely on libxml2 to process XML data, resulting in denial of service.

Technical details

A double-free vulnerability exists in the SAX attributeDecl callback handler in libxml2 when Python bindings are enabled. An attacker can craft an XML document containing a DTD with enumerated attribute values that triggers the vulnerable code path. The memory corruption leads to a reproducible crash in Python applications using libxml2 SAX bindings. The vulnerability is remotely exploitable via network delivery of a malicious XML document and requires no authentication or special privileges. An attacker can achieve denial of service by crashing Python processes that parse untrusted XML input.

Affected products

  • libxml2 Project libxml2 <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References