CVE-2026-8177Patch

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-10); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-10: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Mentions · 2026-06-15: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-06-15: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-15: 105-1005-1405-1506-15
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-101
Disclosure1
2026-05-141
Patch1
2026-05-151
General1
2026-06-151
Patch1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔐 CVE-2026-8177: falha crítica no Perl XML::LibXML afeta servidores SUSE. Script de correção automática + mitigação com AppArmor e iptables. Saiba mais: -> http://tinyurl.com/4x7w7x4a #SUSE https://t.co/3bWBjRUVeQ

    Post summary

    The post announces a critical flaw in Perl XML::LibXML for SUSE servers and provides a script for automatic remediation along with AppArmor and iptables mitigation steps.

    1000054
    1.5K followersView on X
  • Open Source Security mailing list@oss_security
    General

    Perl CPAN CVE-2026-8177: XML::LibXML through 2.0210 read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 https://www.openwall.com/lists/oss-security/2026/05/10/8 CVE-2026-5084: WebDyne::Session through 2.075 generates the session id insecurely https://www.openwall.com/lists/oss-security/2026/05/11/3

    Post summary

    Two Perl module CVEs are announced: one involving out‑of‑bounds heap memory in XML::LibXML and another with insecure session ID generation in WebDyne::Session; no evidence of PoC, exploitation, or patch is provided.

    10000102
    4.6K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Just patched CVE-2026-8177 on my Mageia boxes. ✅ Check version. ✅ Apply script. ✅ Block vectors with iptables. Read more -> https://tinyurl.com/6cytx9tz #Mageia #security https://t.co/JCi3vuHq2n

    Post summary

    The user indicates they have patched CVE-2026-8177 on Mageia using a script and iptables defenses, without detailing the vulnerability or indicating exploitation.

    1000041
    1.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8177 Out-of-Bounds Heap Memory Read in XML::LibXML Perl Through 2.0210 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8177 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post announces CVE-2026-8177, stating it is an out‑of‑bounds heap memory read in XML::LibXML Perl up to version 2.0210 and provides a link to Vulmon for further details.

    0000050
    4.0K followersView on X

Explore more