{"cvss":7.5,"datePublished":"2026-05-10T21:16:30.003","dateUpdated":"2026-09-18T13:18:37.633","description":"XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences.\n\nA node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory.\n\nAny Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.","id":"CVE-2026-8177","raw":{"affected":[{"affectedData":[{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","packageName":"XML-LibXML","product":"XML::LibXML","programFiles":["dom.c"],"repo":"https://github.com/cpan-authors/XML-LibXML","vendor":"SHLOMIF","versions":[{"lessThanOrEqual":"2.0210","status":"affected","version":"0","versionType":"custom"}]}],"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"affectedData":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"defaultStatus":"affected","packageName":"perl-XML-LibXML","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1:2.0210-4.el10_2.1","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"defaultStatus":"affected","packageName":"perl-XML-LibXML","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1:2.0210-4.el10_0.1","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:enterprise_linux:8"],"defaultStatus":"affected","packageName":"perl-XML-LibXML","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1:2.0132-3.el8_10","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:enterprise_linux:9"],"defaultStatus":"affected","packageName":"perl-XML-LibXML","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1:2.0206-5.el9_8.1","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:rhel_e4s:9.2"],"defaultStatus":"affected","packageName":"perl-XML-LibXML","product":"Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1:2.0206-5.el9_2.1","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"defaultStatus":"affected","packageName":"perl-XML-LibXML","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1:2.0206-5.el9_4.1","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"defaultStatus":"affected","packageName":"perl-XML-LibXML","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1:2.0206-5.el9_6.1","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:6"],"defaultStatus":"unknown","packageName":"perl-XML-LibXML","product":"Red Hat Enterprise Linux 6","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:7"],"defaultStatus":"affected","packageName":"perl-XML-LibXML","product":"Red Hat Enterprise Linux 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"unaffected","packageName":"openshift/ose-rhel-coreos-8","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"unaffected","packageName":"openshift/ose-rhel-coreos-9","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"}],"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"cveTags":[],"descriptions":[{"lang":"en","value":"XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences.\n\nA node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory.\n\nAny Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service."},{"lang":"es","value":"Las versiones de XML::LibXML hasta la 2.0210 para Perl leen memoria del heap fuera de límites al analizar nombres de nodos XML que contienen secuencias de bytes UTF-8 truncadas.\n\nUn nombre de nodo que termina en medio de una secuencia UTF-8 multibyte hace que el analizador lea más allá del final de la cadena de entrada hacia la memoria del heap adyacente.\n\nCualquier proceso Perl que pasa cadenas controladas por el atacante a los métodos de nombre de nodo DOM de XML::LibXML puede alcanzar esta ruta en la API predeterminada. La consecuencia probable es un fallo, causando denegación de servicio."}],"id":"CVE-2026-8177","lastModified":"2026-09-18T13:18:37.633","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"exploitabilityScore":3.9,"impactScore":3.6,"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"exploitabilityScore":3.9,"impactScore":3.6,"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-8177","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-05-11T16:34:46.706997Z","version":"2.0.3"}}]},"published":"2026-05-10T21:16:30.003","references":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","url":"https://github.com/cpan-authors/XML-LibXML/commit/15652bd905a6c9dda59a81b14d4766adbbae2ea8.patch"},{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","url":"https://github.com/cpan-authors/XML-LibXML/issues/146"},{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","url":"https://github.com/cpan-authors/XML-LibXML/pull/149"},{"source":"af854a3a-2127-422b-91ae-364da2661108","url":"http://www.openwall.com/lists/oss-security/2026/05/10/8"},{"source":"af854a3a-2127-422b-91ae-364da2661108","url":"http://www.openwall.com/lists/oss-security/2026/05/11/2"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:39547"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:39553"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:39878"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:68632"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:68685"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:68688"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:68693"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/security/cve/CVE-2026-8177"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2468684"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8177.json"}],"sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","vulnStatus":"Deferred","weaknesses":[{"description":[{"lang":"en","value":"CWE-125"}],"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"description":[{"lang":"en","value":"CWE-125"}],"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]},"severity":"HIGH","source":"nvd","title":"XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing tr..."}