🛡️ AZL-74783 — libxml2
Description
CVE-2026-0992 affecting package libxml2 2.11.5-8
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.
Affected software
AZL-74783 is recorded against 1 package.
- libxml2
Timeline and source
Published on 15 January 2026 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| libxml2 | — | — |
References
Similar Threats
- Unknown ALPINE-CVE-2025-49794
- Unknown ALPINE-CVE-2025-49795
- Unknown ALPINE-CVE-2025-49796
- Unknown ALPINE-CVE-2025-6021
- Unknown ALPINE-CVE-2025-32415
More AZL 7 advisories
Browse all of AZL 7 in the advisory index.
Free Vulnerability Check
Is your site affected by AZL-74783?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-74783 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.