PT-2025-46055 · Julia · Xml2 Jll

Published

2025-10-17

·

Updated

2025-10-17

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the '0' value).
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2025-80

Affected Products

Xml2 Jll