Ubuntu advisory USN-8910-1: libxml2 flaws with risk of denial of service, XXE and SSRF
The Ubuntu security advisory USN-8910-1 describes six vulnerabilities in libxml2, with risks of denial of service, code execution, XML external entity injection and server-side request forgery. One of them affects only Ubuntu 26.04 LTS.
Source: USN-8910-1: vulnerabilidades no libxml2 (ubuntu.com). Text prepared with AI from this source.
What happened and what to do
The Ubuntu security advisory USN-8910-1 describes six vulnerabilities in libxml2, an XML parsing library used by many programs. They can cause denial of service (CVE-2026-76781, CVE-2026-86138, CVE-2026-86139, CVE-2026-86142, CVE-2026-86143 and CVE-2026-86144). Some may allow arbitrary code execution (CVE-2026-86138 and CVE-2026-86142). CVE-2026-86144 allows XML external entity injection or server-side request forgery when XInclude directives are processed without parser options such as disabling network access. CVE-2026-86139 affects only Ubuntu 26.04 LTS.
A company can start by mapping which services, pipelines and applications depend on libxml2, including through third-party libraries, and which of them process XML from external sources. It should then apply the package updates published by Ubuntu on those hosts and containers, prioritizing those that receive untrusted input. As a complementary measure, it is advisable to review the XInclude and network access settings in XML parsers. Wendelmaques can diagnose this exposure, build an automated inventory of libxml2 versions with a dashboard tracking fixes, and implement the collection and monitoring within the client's environment.
How the consultancy can help
Diagnosis of libxml2 exposure in the client's environment, inventory of versions and dependencies, and implementation of a patch-monitoring dashboard, run on the client's own infrastructure.
Next step
Send a short description of your scenario, including the systems that process XML and the current state of updates, and receive a scoped proposal for diagnosis and implementation.
Consulting for your project
Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.
Quoted per project
Request a proposal