MEDIUM
CVE-2026-76781
CVSS
5.5
Description
A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).
Weakness (CWE)
CWE-476
NULL Pointer Dereference
EPSS Score
0.16%
Probability of exploitation in next 30 days
5.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.