CVE-2026-86141

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-05 05:17

Updated : 2026-09-15 19:37


NVD link : CVE-2026-86141

Mitre link : CVE-2026-86141

CVE.ORG link : CVE-2026-86141


JSON object : View

Products Affected

xmlsoft

  • libxml2
CWE
CWE-252

Unchecked Return Value