Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Not in CISA KEV

CVE-2026-6653 — libxml2

CVE-2026-6653 is a Use After Free vulnerability. A fix is available — see the affected versions and patch details below.

libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling

Published
Updated
Affected
1 product
Patched
See advisory
Exploits
None indexed
Exploitation data as of Oct 8, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-6653.

EPSS Exploitation Probability

via FIRST.org ↗
0.4%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs27th percentile — riskier than 27% of all scored CVEsHighest risk
0.00%0.29%0.57%0.85%0.3%0.4%0.4%0.4%0.4%Jul 26Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Description

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

Affected Products

1 product · 1 configurations
Application
libxml2xmlsoft
≥ 2.9.11 && ≤ 2.11.0
range

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Fix

    Upgrade the affected component to the fixed release for CVE-2026-6653, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.

  3. Workarounds

    Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatModerate

This Moderate impact use-after-free vulnerability in libxml2 can lead to a denial of service in Red Hat products that process untrusted XML input. In the worst-case scenario, a remote attacker is able to provide specially crafted XML, which, if parsed by an affected application, could cause the application to crash.

Workaround published by Red Hat
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Updating to a fixed version of libxml2 (2.11.0 or later upstream, or a future RHEL errata) will fully resolve this issue.
Source: Red Hat security advisory for CVE-2026-6653 (CC BY 4.0)
ProductFixed inAdvisory
Red Hat Enterprise Linux 8libxml2-0:2.9.7-21.el8_10.8RHSA-2026:69655
Red Hat Enterprise Linux 9libxml2-0:2.9.13-14.el9_8.4RHSA-2026:61247
Cert Manager support for Red Hat OpenShift release 1.20cert-manager/jetstack-cert-manager-rhel9:1790223279RHSA-2026:72394
Cert Manager support for Red Hat OpenShift release 1.20cert-manager/cert-manager-istio-csr-rhel9:1790223719RHSA-2026:72395
Cert Manager support for Red Hat OpenShift release 1.20cert-manager/cert-manager-operator-rhel9:1790272426RHSA-2026:72399
Cert Manager support for Red Hat OpenShift release 1.20cert-manager/jetstack-cert-manager-acmesolver-rhel9:1790589998RHSA-2026:72470
Cert Manager support for Red Hat OpenShift release 1.20cert-manager/cert-manager-istio-csr-rhel9:1790589914RHSA-2026:72475
Cert Manager support for Red Hat OpenShift release 1.20cert-manager/cert-manager-operator-rhel9:1790589855RHSA-2026:72476
UbuntuCRITICAL

Frequently Asked Questions

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
O3 Security · Impact-Aware SCA

Is CVE-2026-6653 in your dependencies?

Find it across , including transitive dependencies.

CVE-2026-6653: libxml2