
CVE-2026-6653: libxml2: Use after free in xmlParseInternalSubset (>=2.9.11, <2.11.0) https://www.openwall.com/lists/oss-security/2026/06/22/3 due to improper entity resolution handling. A remote attacker could possibly use this issue to crash or possibly run arbitrary programs. PoC and reproduction instructions.
Post summary
This post announces the use‑after‑free vulnerability CVE‑2026‑6653 in libxml2, provides technical details and a PoC, but does not report active exploitation, a patch, or a false positive.



