Security Advisory
CVE-2026-86141
2.9
LOW
Vulnerability Description
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
Published Date
September 5, 2026
Official Source
NIST NVD Advisory