A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.
{
"github_reviewed": true,
"severity": "MODERATE",
"cwe_ids": [
"CWE-476"
],
"nvd_published_at": "2021-05-14T20:15:00Z",
"github_reviewed_at": "2023-07-05T21:11:25Z"
}