PT-2026-39540 · Cpan+1 · Xml-Libxml+1

·

CVE-2026-8177

·

Published

2026-05-10

·

Updated

2026-08-20

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions XML::LibXML versions prior to 2.0211
Description XML::LibXML for Perl reads out-of-bounds heap memory when parsing XML node names that contain truncated UTF-8 byte sequences. A node name ending in the middle of a multi-byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process passing attacker-controlled strings to DOM node-name methods can trigger this issue on the default API, likely resulting in a crash and denial of service.
Recommendations Update to version 2.0211 or later.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:39547
ALSA-2026:39553
ALSA-2026:39878
AZL-86550
CVE-2026-8177
ECHO-D531-9D26-AC4F
OESA-2026-3404
OPENSUSE-SU-2026:10854-1
OPENSUSE-SU-2026:20908-1
RHSA-2026:39547
RHSA-2026:39553
RHSA-2026:39878
SUSE-SU-2026:22081-1
SUSE-SU-2026:2324-1
SUSE-SU-2026:2402-1

Affected Products

Rocky Linux
Xml-Libxml