Vulnerability Details CVE-2026-6732
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 46.2%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-6732
-
-
cpe:2.3:a:ibm:vios:4.1.0.10
-
cpe:2.3:a:ibm:vios:4.1.0.20
-
cpe:2.3:a:ibm:vios:4.1.0.21
-
cpe:2.3:a:ibm:vios:4.1.0.30
-
cpe:2.3:a:ibm:vios:4.1.0.40
-
-
cpe:2.3:a:ibm:vios:4.1.1.0
-
cpe:2.3:a:ibm:vios:4.1.1.10
-
cpe:2.3:a:ibm:vios:4.1.1.20
-
cpe:2.3:a:ibm:vios:4.1.2.0
-
cpe:2.3:a:redhat:hardened_images:-
-
cpe:2.3:a:redhat:jboss_core_services:-
-
cpe:2.3:a:redhat:openshift_container_platform:4.0
-
cpe:2.3:a:xmlsoft:libxml2:2.13.0
-
cpe:2.3:a:xmlsoft:libxml2:2.13.1
-
cpe:2.3:a:xmlsoft:libxml2:2.13.2
-
cpe:2.3:a:xmlsoft:libxml2:2.13.3
-
cpe:2.3:a:xmlsoft:libxml2:2.13.4
-
cpe:2.3:a:xmlsoft:libxml2:2.13.5
-
cpe:2.3:a:xmlsoft:libxml2:2.13.6
-
cpe:2.3:a:xmlsoft:libxml2:2.13.8
-
cpe:2.3:a:xmlsoft:libxml2:2.13.9
-
cpe:2.3:a:xmlsoft:libxml2:2.14.0
-
cpe:2.3:a:xmlsoft:libxml2:2.14.1
-
cpe:2.3:a:xmlsoft:libxml2:2.14.2
-
cpe:2.3:a:xmlsoft:libxml2:2.14.3
-
cpe:2.3:a:xmlsoft:libxml2:2.14.4
-
cpe:2.3:a:xmlsoft:libxml2:2.14.5
-
cpe:2.3:a:xmlsoft:libxml2:2.14.6
-
cpe:2.3:a:xmlsoft:libxml2:2.15.0
-
cpe:2.3:a:xmlsoft:libxml2:2.15.1
-
cpe:2.3:a:xmlsoft:libxml2:2.15.2
-
-
cpe:2.3:o:ibm:aix:7.2.5.0
-
cpe:2.3:o:ibm:aix:7.2.5.1
-
-
-
-
cpe:2.3:o:redhat:enterprise_linux:10.0
-
cpe:2.3:o:redhat:enterprise_linux:6.0
-
cpe:2.3:o:redhat:enterprise_linux:7.0
-
cpe:2.3:o:redhat:enterprise_linux:8.0
-
cpe:2.3:o:redhat:enterprise_linux:9.0