CVE-2026-88385

Description

A flaw was found in mxml. A remote attacker could cause a Denial of Service (DoS) by supplying specially crafted, malformed XML data to an application utilizing the library. When handling parsing errors, the parser fails to release certain allocated text nodes, leading to a persistent memory leak on each parsing attempt. Over repeated requests, this uncontrolled memory accumulation can exhaust system memory and result in application unavailability.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (Other); DoS: Resource Consumption (Memory); DoS: Resource Consumption (CPU)

An attacker that can influence the allocation of resources that are not properly released could deplete the available resource pool and prevent all other processes from accessing the same type of resource. Frequently-affected resources include memory, CPU, disk space, power or battery, etc.

Frequently Asked Questions

Want to get errata notifications? Sign up here.