Beveiligingsadvies

CVE-2026-0989

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-01-15 14:20:23
Laatst bijgewerkt 2026-09-01 12:10:22
Toegewezen door redhat
CVSS-score 3.7
Status PUBLISHED

Beschrijving

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.