Sploitus

CVE-2026-6653

No indexed exploits for CVE-2026-6653 yet

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

Affected products
Linuxmint, Ubuntu, Libxml2
Xmlsoft libxml2
≤ 2.11.0
CVSS 3.1
9.8 CRITICAL
EPSS
0.4% (28th percentile)
Weakness
CWE-611, CWE-416
NVD status
Analyzed
Published
2026-06-22
Attack patterns
CAPEC-242

Fix

Upgrade to libxml2 version 2.11.0 or later

CVE-2026-6653 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-6653 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-6653 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.