In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XMLPARSENONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).
{
"cwe_ids": [
"CWE-669"
],
"cna_assigner": "mitre",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"fixed": "2.15.4"
}
]
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "2.15.4"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"introduced": "libxml2"
},
{
"fixed": "2.15.4"
}
]
}
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86144.json"
}[
{
"target": {
"file": "xinclude.c"
},
"deprecated": false,
"id": "CVE-2026-86144-0f7c0bc9",
"signature_version": "v1",
"digest": {
"line_hashes": [
"34145760026945687568632009577657942223",
"219710457047021824442605161850739489425",
"235012464000529242691134553369470467122",
"135714532679754293974993042542848835233",
"186626338196798356969412560906995264145",
"15677044944407925380340882923766271361",
"171523655231842818645338080066431004349",
"244092497581654226430004458575768044569",
"213959534017002599254781236750057580802",
"216571362707139326316215284630135298255",
"56423275120156758795947033955569189730",
"221997084649447532667757482745436473803",
"266606668701255461755171177961398160377",
"2643740467914354775633040399176276421",
"52823438810584912289884058640857191249"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/gnome/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61"
},
{
"target": {
"file": "xinclude.c",
"function": "xmlXIncludeLoadTxt"
},
"deprecated": false,
"id": "CVE-2026-86144-0f7c4ff9",
"signature_version": "v1",
"digest": {
"function_hash": "118464514973552658019226948772494938469",
"length": 3748.0
},
"signature_type": "Function",
"source": "https://github.com/gnome/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61"
},
{
"target": {
"file": "runtest.c"
},
"deprecated": false,
"id": "CVE-2026-86144-a94dcf44",
"signature_version": "v1",
"digest": {
"line_hashes": [
"322244894967541891504013150835923570967",
"329267464626600955848418372937782588247",
"335650984949389900143881790103795206194",
"176127790847955742402066819618998790322",
"187089333812840946346118950588913694785",
"90840705574842022346971589415511613621",
"298828233619572368649291476277747993558"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/gnome/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61"
},
{
"target": {
"file": "xinclude.c",
"function": "xmlXIncludeProcess"
},
"deprecated": false,
"id": "CVE-2026-86144-b8f10e8d",
"signature_version": "v1",
"digest": {
"function_hash": "132773337586947596947468483873155219454",
"length": 72.0
},
"signature_type": "Function",
"source": "https://github.com/gnome/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61"
},
{
"target": {
"file": "xinclude.c",
"function": "xmlXIncludeProcessTree"
},
"deprecated": false,
"id": "CVE-2026-86144-caf1fb5a",
"signature_version": "v1",
"digest": {
"function_hash": "132773337586947596947468483873155219454",
"length": 72.0
},
"signature_type": "Function",
"source": "https://github.com/gnome/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86144.json"
"2026-09-06T08:01:50Z"