PT-2026-91909 · Azure Linux · Libxml2
Published
2026-09-05
·
Updated
2026-09-05
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML PARSE NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libxml2