CVE-2026-0989

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-15 15:15

Updated : 2026-01-16 15:55


NVD link : CVE-2026-0989

Mitre link : CVE-2026-0989

CVE.ORG link : CVE-2026-0989


JSON object : View

Products Affected

No product.

CWE
CWE-674

Uncontrolled Recursion