CVE-2022-49043: Xmlsoft LIBXML2

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.

Affected products

  • Xmlsoft LIBXML2: before 2.11.0 (fixed in 2.11.0)

Published 2025-01-26. Last modified 2026-06-17.