Multiple CVEs Affecting XML Libraries Published on February 18, 2026

Multiple CVEs Affecting XML Libraries Published on February 18, 2026

First seen 18 Feb 2026, 10:13 UTC Pro-Linux.DeApi.Msrc.Microsoft 41.1

Article Content

Browse articles
ThreatCluster

Two new Common Vulnerabilities and Exposures (CVEs) were published on February 18, 2026. CVE-2022-49043 affects libxml2 versions before 2.11.0, introducing a use-after-free vulnerability, while CVE-2024-28757 in libexpat versions up to 2.6.1 allows for XML Entity Expansion attacks when using external parsers. Both vulnerabilities could impact applications relying on these libraries for XML processing.

Timeline

2024-03-10
CVE-2024-28757 published
2025-01-26
CVE-2022-49043 published
2026-02-18
CVE-2022-49043 and CVE-2024-28757 information published