CVE-2026-86140: Buffer Overflow
Published Sep 5, 2026
·Updated
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
Affected Software
1 affected component
libxml2 libxml2<2.15.4
Event History
Sep 5, 2026
CVE Published
via MITRE·04:26 AM
Data Sourced
via MITRE·04:26 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
libxml2 versions before 2.15.4 are affected. Systems using version 2.15.4 or later are not identified as affected by the provided data.
2
What access does an attacker need?
The listed attack vector is local. The vulnerability is rated as requiring no privileges and no user interaction.
3
What could successful exploitation impact?
The severity vector indicates high confidentiality and integrity impact, with low availability impact.
4
How can I determine whether I need to remediate?
Identify the libxml2 version installed or bundled with the affected application. Remediate installations running a version earlier than 2.15.4.