THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86143 (MEDIUM 6.9) — In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length

[NVD] CVE-2026-86143 (MEDIUM 6.9) — In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length

mednvdPublished 2026-09-05

CVE-2026-86143 CVSS: 6.9 MEDIUM Published: 2026-09-05T05:17:13.270

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86143