CVE-2026-1757

Source
https://cve.org/CVERecord?id=CVE-2026-1757
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1757.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-1757
Downstream
Related
Published
2026-02-02T13:15:58.580Z
Modified
2026-03-23T05:07:19.377728834Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1757.json"