← CVE Tracker
8.1HIGH

CVE-2024-34394 — libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while…

Unknown · Unknown · Published 2 May 2024 · Modified 3 Oct 2026

Description

libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.

References

What to do
  1. Check whether Unknown is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2024-34394