PT-2026-91909 · Azure Linux · Libxml2

Published

2026-09-05

·

Updated

2026-09-05

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML PARSE NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-99702

Affected Products

Libxml2