Overview
What is CVE-2026-86142?
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
Vulnerability intelligence
CVE-2026-86142 and is rated Medium severity with a CVSS score of 6.9. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.