Vulnerabilidad · Publicado 08/09/2026
Se ha identificado un fallo en libxml2 (cuando está compilado con bindings de Python) que permite a atacantes remotos provocar una denegación de servicio mediante documentos XML especialmente diseñados con Definiciones de Tipo de Documento (DTD) que contienen valores de atributos enumerados. La vulnerabilidad explota un error de doble liberación de memoria en el manejador de retrollamada SAX attributeDecl, afectando potencialmente servidores web, APIs y aplicaciones que procesan XML en entornos LATAM.
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
Score: 8.5/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-763
Publicado en NIST NVD.