Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-45322

20
FAUCET Score

CVE-2023-45322 is a use-after-free vulnerability in libxml2 versions through 2.11.5, specifically within the xmlUnlinkNode function in tree.c, which can only manifest after a memory allocation failure. This vulnerability carries a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to high availability impact. Despite its technical nature, the vendor considers it non-critical due to the attacker's inability to control memory allocation failures. Currently, there is no evidence of active exploitation, nor are there public exploit modules or significant community discussion, though it was mentioned in a GitLab security release.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.11.5CPE matchmatch criteria
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.83%
Probability of exploitation in next 30 days
EPSS Percentile
53.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0083 is in the 62nd percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: cbl2 libxml2 2.10.4-2 on CBL Mariner 2.0Fixed in: 2.10.4-2
microsoftpatch availablevia msrc
Product: azl3 libxml2 2.11.5-3 on Azure Linux 3.0Fixed in: 2.11.5-3
microsoftpatch availablevia msrc
Product: azl3 libxml2 2.11.5-5 on Azure Linux 3.0Fixed in: 2.11.5-3
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libxml2
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Core ServicesFixed in: libxml2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libxml2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: libxml2

Vendor Advisories (2)

microsoft2023-Oct/CVE-2023-45322Moderate

libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."

Oct 10, 2023
redhatCVE-2023-45322Low

libxml2: use-after-free in xmlUnlinkNode() in tree.c

Aug 23, 2023

References

lists.debian.org / debian-lts-announce/2025/02/msg00028.html
gitlab.gnome.org / GNOME/libxml2/-/issues/344
Issue TrackingPatchVendor Advisory
gitlab.gnome.org / GNOME/libxml2/-/issues/583
Issue TrackingPatchVendor Advisory
openwall.com / lists/oss-security/2023/10/06/5
Mailing ListPatchThird Party Advisory