ThreatCluster

Multiple CVEs Identified in TinyXML2 Affecting Application Stability

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 34

Article Content

Browse articles
ThreatCluster

Two vulnerabilities, CVE-2024-50614 and CVE-2024-50615, have been identified in TinyXML2 versions up to 10.0.0. Both vulnerabilities involve reachable assertions in the XMLUtil::GetCharacterRef function, which may lead to application exits. Affected users should be aware of these issues as they could impact application performance.

Timeline

2024-10-27
CVE-2024-50614 published
2024-10-27
CVE-2024-50615 published
2026-02-18
Information published regarding vulnerabilities