Vulnerability CVE-2024-34394


Published: 2024-05-02

Description:
libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.

 References:
https://research.jfrog.com/vulnerabilities/libxmljs2-namespaces-type-confusion-rce-jfsa-2024-001034098/
https://github.com/marudor/libxmljs2/issues/205

Copyright 2026, cxsecurity.com

 

Back to Top