Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-468

JLSEC-2026-468

JLSEC Published
Modified
Affected Packages
XML2_jll >= 2.11.5+0, < 2.13.3+0
Aliases / Upstream
CVE-2024-40896

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

References