Libxmljs is a Node.js library that wraps XML processing functionality, and it maintains a focused but notably exposed attack surface given its role as a parsing interface sitting between application logic and untrusted XML input. The durable signal in its vulnerability profile centers on type-confusion issues, improper input validation, and uncontrolled resource consumption, which are characteristic of the memory and parsing complexity inherent to XML processors handling attacker-controlled documents. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libxmljs Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-34391CRITICAL libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. T | May 2, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-34392CRITICAL libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on | May 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-25341HIGH A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and entity_decl nodes causes a segme | Dec 26, 2025 | 7.5 | 25 | NO | NO |
CVE-2022-21144HIGH This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invoking the .toString method of the | May 1, 2022 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libxmljs Project.
Media articles that mention a CVE ID that affects a product developed by Libxmljs Project — matched by CVE ID, not by vendor name.