CVE-2026-6653Disclosure(xmlsoft / libxml2)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416CWE-611

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libxml2

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-06-22); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
libxml2

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-22: 3Mentions · 2026-06-25: 1PoC Mentioned / Linked · 2026-06-25: 1Technical Details · 2026-06-22: 3Technical Details · 2026-06-25: 106-2206-25
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-223
Disclosure3
2026-06-251
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-6653: libxml2: Use after free in xmlParseInternalSubset (>=2.9.11, <2.11.0) https://www.openwall.com/lists/oss-security/2026/06/22/3 due to improper entity resolution handling. A remote attacker could possibly use this issue to crash or possibly run arbitrary programs. PoC and reproduction instructions.

    Post summary

    This post announces the use‑after‑free vulnerability CVE‑2026‑6653 in libxml2, provides technical details and a PoC, but does not report active exploitation, a patch, or a false positive.

    00000284
    4.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6653 Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously cra… https://www.cve.org/CVERecord?id=CVE-2026-6653 ----- Traducción: CVE-2026-6653 Use… http://infoflow.cloud`

    Post summary

    The post provides a brief disclosure of a use‑after‑free vulnerability in libxml2 that can cause denial of service, with no PoC, exploit tool, active exploitation claim, or patch information.

    0000040
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6653 Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously cra… https://www.cve.org/CVERecord?id=CVE-2026-6653

    Post summary

    The tweet announces CVE-2026-6653, noting a use-after-free that causes a denial‑of‑service in libxml2, and links to the official CVE record.

    00000707
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6653 Use After Free in GNOME libxml2 2.9.11 to 2.11.0 Denial-of-Service https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6653 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    This post announces the CVE‑2026‑6653 use‑after‑free vulnerability in GNOME libxml2 that can cause a denial‑of‑service, but it provides no proof‑of‑concepts, exploits, or patch information.

    00000129
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxmlsoftlibxml2---

Explore more