Xmlsoft maintains a compact but critically pervasive library ecosystem—principally libxml2 and libxslt—that sits deep in the software supply chain and is embedded across a vast range of servers, applications, parsers, and system utilities. Despite a very narrow product portfolio, the vendor's vulnerability footprint is substantial and broadly consequential because a single flaw in an XML or XSLT parser can propagate to every downstream product that links the library, and vulnerabilities affecting it skew toward serious outcomes with an elevated tendency to reach critical severity. The recurring weakness classes—buffer-boundary violations, use-after-free conditions, out-of-bounds reads, and NULL-pointer dereferences—reflect the memory-safety challenges inherent to C-language parsers that process untrusted and complex markup structures at scale. Defenders should inventory products that bundle these libraries rather than tracking the libraries alone, since remediation depends on downstream vendors patching and rebuilding; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xmlsoft over time
Signals from CVEs in this vendor scope (136 CVEs).
136 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3529HIGH Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or ex | Sep 12, 2008 | 10.0 | 54 | NO | YES |
CVE-2004-0989HIGH Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is no | Mar 1, 2005 | 10.0 | 49 | NO | YES |
CVE-2011-1944HIGH Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service | Sep 2, 2011 | 9.3 | 47 | NO | YES |
CVE-2017-7376CRITICAL Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects. | Feb 19, 2018 | 9.8 | 44 | NO | NO |
CVE-2004-0110HIGH Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL. | Mar 15, 2004 | 7.5 | 44 | NO | YES |
CVE-2026-6653CRITICAL Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML inp | Jun 22, 2026 | 9.8 | 40 | NO | NO |
CVE-2021-30560HIGH Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Aug 3, 2021 | 8.8 | 39 | NO | NO |
CVE-2022-40303HIGH An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. T | Nov 23, 2022 | 7.5 | 38 | NO | NO |
CVE-2016-4658CRITICAL xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in | Sep 25, 2016 | 9.8 | 37 | NO | NO |
CVE-2026-11979HIGH libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-siz | Jun 29, 2026 | 7.8 | 36 | NO | NO |
Signals from CVEs in this vendor scope (136 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xmlsoft.
Media articles that mention a CVE ID that affects a product developed by Xmlsoft — matched by CVE ID, not by vendor name.