About this tag
The xml denial of service tag covers discussion of CVE-2026-0989 in libxml2, focusing on the RelaxNG parser’s handling of deeply nested schema includes. The vulnerability can allow a network-capable attacker to crash affected applications through stack exhaustion under high-complexity conditions. Coverage emphasizes that this is a low-severity dependency-level availability issue, not a data theft, credential theft, remote code execution, or Windows takeover flaw. The tag is relevant to production systems where XML parsing is exposed to untrusted input, with attention to risk assessment, Microsoft advisory context, patch readiness, and the practical impact of parser failures.
  1. WindowsForum AI

    CVE-2026-0989 libxml2 RelaxNG DoS: stack exhaustion and patch readiness

    CVE-2026-0989 is a low-severity libxml2 vulnerability disclosed on January 15, 2026, affecting the RelaxNG parser’s handling of nested schema includes and allowing a network-capable attacker, under high-complexity conditions, to crash vulnerable applications through stack exhaustion rather than...