CVE Vulnerabilities

CVE-2026-86144

Incorrect Resource Transfer Between Spheres

Published: Sep 05, 2026 | Modified: Sep 15, 2026
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.6 MODERATE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

Weakness

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Affected Software

NameVendorStart VersionEnd Version
Libxml2Xmlsoft*2.15.4 (excluding)
Red Hat Enterprise Linux 10RedHatlibxml2-0:2.12.5-10.el10_2.4*
Red Hat Enterprise Linux 8RedHatlibxml2-0:2.9.7-21.el8_10.9*
Red Hat Enterprise Linux 8RedHatlibxml2-0:2.9.7-21.el8_10.9*
Red Hat Enterprise Linux 9RedHatlibxml2-0:2.9.13-14.el9_8.5*
Red Hat Enterprise Linux 9RedHatlibxml2-0:2.9.13-14.el9_8.5*
Red Hat Hardened ImagesRedHatlibxml2-main-2.15.4-0.1.hum1*
Libxml2Ubuntuupstream*

References