CVE-2026-6653 — libxml2
CVE-2026-6653 is a Use After Free vulnerability. A fix is available — see the affected versions and patch details below.
libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-6653.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Description
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
Affected Products
libxml2xmlsoftDetection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Fix
Upgrade the affected component to the fixed release for CVE-2026-6653, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.
Workarounds
Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
This Moderate impact use-after-free vulnerability in libxml2 can lead to a denial of service in Red Hat products that process untrusted XML input. In the worst-case scenario, a remote attacker is able to provide specially crafted XML, which, if parsed by an affected application, could cause the application to crash.
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Updating to a fixed version of libxml2 (2.11.0 or later upstream, or a future RHEL errata) will fully resolve this issue.Source: Red Hat security advisory for CVE-2026-6653 (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Enterprise Linux 8 | libxml2-0:2.9.7-21.el8_10.8 | RHSA-2026:69655 |
| Red Hat Enterprise Linux 9 | libxml2-0:2.9.13-14.el9_8.4 | RHSA-2026:61247 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/jetstack-cert-manager-rhel9:1790223279 | RHSA-2026:72394 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/cert-manager-istio-csr-rhel9:1790223719 | RHSA-2026:72395 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/cert-manager-operator-rhel9:1790272426 | RHSA-2026:72399 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/jetstack-cert-manager-acmesolver-rhel9:1790589998 | RHSA-2026:72470 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/cert-manager-istio-csr-rhel9:1790589914 | RHSA-2026:72475 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/cert-manager-operator-rhel9:1790589855 | RHSA-2026:72476 |
Frequently Asked Questions
Is CVE-2026-6653 in your dependencies?
Find it across , including transitive dependencies.