CVE-2026-74860: Libxml2: double-free/uaf in libxml2 python bindings

Published Sep 8, 2026
·
Updated

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.

Affected Software

1 affected component
libxml2 libxml2

Event History

Sep 8, 2026
CVE Published
via MITRE·11:27 AM
Data Sourced
via MITRE·11:27 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which applications are exposed to this issue?

Python applications that use the libxml2 SAX bindings are exposed when they parse attacker-controlled XML. The vulnerable condition requires libxml2 to be built or used with Python bindings enabled.

2

What must an attacker provide to trigger the flaw?

An attacker needs to supply a specially crafted XML document containing a DTD with enumerated attribute values. Exploitation is remote, but the attacker must be able to cause the application to parse that XML.

3

What is the confirmed impact?

The described, reproducible impact is a crash and resulting denial of service in affected Python applications. The underlying error is a double-free in the SAX attributeDecl callback handler.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203