CVE-2024-34394
Executive Summary
CVE-2024-34394 exposes a type‑confusion flaw in libxmljs2 when parsing crafted XML that triggers the namespaces() call on a grand‑child node referencing an entity. The bug can cause denial‑of‑service and potentially remote code execution. The vulnerability is not yet listed in the CISA KEV database.
Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2024-05-02T19:15:06.630 - Last Modified: 2026-10-03T10:16:38.343
Original Description: libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.
"Edison failed 10,000 times before he made the electric light. Do not be discouraged if you fail a few times."
— Napoleon Hill