Junglewise Threat Intelligence

CVE-2026-8177: XML::LibXML out-of-bounds read in domParseChar

CVE-2026-8177 · Severity: high · CVSS 7.5 · Published 2026-05-10

Technologies: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9. Vendors: Red Hat.

Executive brief

XML::LibXML is a popular Perl library used to process and manipulate XML data. A flaw in how it handles specific text characters allows an attacker to provide a specially crafted XML tag name that causes the application to crash. This can lead to a denial-of-service, disrupting business operations that rely on processing external XML data.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the domParseChar() function of XML::LibXML. When the parser encounters a multi-byte UTF-8 leading byte at the end of a string (truncated sequence), it fails to validate the existence of continuation bytes and reads past the NUL terminator into adjacent heap memory. This can be triggered via any DOM method that validates node names, such as createElement or setNodeName, when processing attacker-controlled strings. The primary impact is a process crash (denial of service) if the read hits unmapped memory. A patch is available that replaces the custom UTF-8 parsing logic with libxml2's native xmlValidateName function.

Affected products

  • SHLOMIF XML::LibXML through 2.0210
  • Red Hat Enterprise Linux 6
  • Red Hat Enterprise Linux 7
  • Red Hat Enterprise Linux 8
  • Red Hat Enterprise Linux 9
  • Red Hat Enterprise Linux 10

Timeline

  • 2026-05-08: patched: Upstream fix merged in GitHub repository.
  • 2026-05-10: disclosed: Public disclosure via oss-security mailing list.
  • 2026-05-10: advisory

References

Related threats