CVE-2026-86139: Integer Overflow
Published Sep 5, 2026
·Updated
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
Affected Software
2 affected components
libxml2 libxml2<2.15.4
Xmlsoft Libxml2<2.15.4
Remediation
Event History
Sep 5, 2026
CVE Published
via MITRE·04:23 AM
Data Sourced
via MITRE·04:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 6, 2026
Data Sourced
via Microsoft·11:36 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What conditions are required to exploit this issue?
The vulnerability is locally exploitable and has high attack complexity. The supplied vector indicates no privileges or user interaction are required.
2
Which installations should be considered affected?
Installations using libxml2 before version 2.15.4 should be considered affected. The issue is in the xmlURIEscapeStr function in uri.c.
3
What should teams do if they cannot update immediately?
The provided information does not identify a workaround or configuration mitigation. Prioritize upgrading libxml2 to version 2.15.4 or later when possible.