CVE-2024-34393
Executive Summary
CVE-2024-34393 exposes libxmljs2 to a type‑confusion flaw triggered by a crafted XML document. When attrs() is called on a parsed node, the library may crash (DoS), leak data, enter an infinite loop, or, on 32‑bit systems with XML_PARSE_HUGE enabled, allow remote code execution. The vulnerability is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2024-05-02T19:15:06.480 - Last Modified: 2026-10-03T09:17:03.720
Original Description: libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data leak, infinite loop and remote code execution (on 32-bit systems with the XML_PARSE_HUGE flag enabled).
"Adversity has the effect of eliciting talents, which in prosperous circumstances would have lain dormant."
— Horace