Overview
What is CVE-2026-86141?
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
Vulnerability intelligence
CVE-2026-86141 and is rated Low severity with a CVSS score of 2.9. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.