CVE-2026-0992

All FrameworksJBoss/WildFlyCWE-400CVE-2026-0992

CVE-2026-0992

State: PUBLISHED · Published: 2026-01-15 · Updated: 2026-04-21 · Assigner: redhat
Description
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2026/0xxx/CVE-2026-0992.json