CVE-2017-16932: Xmlsoft LIBXML2

High severity, CVSS 7.5. EPSS: 5.9% chance of exploitation in the next 30 days.

parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.

Affected products

  • Xmlsoft LIBXML2: up to and including 2.9.4

Published 2017-11-23. Last modified 2026-06-17.