ECHO-778a-550a-1fd5

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-778a-550a-1fd5.json
JSON Data
https://api.test.osv.dev/v1/vulns/ECHO-778a-550a-1fd5
Upstream
Withdrawn
2026-05-06T18:45:01Z
Published
2026-05-07T18:28:28Z
Modified
2026-09-15T00:47:46Z
Summary
Type confusion in xmlParseReference (ctxt vs ctxt->userData in SAX callbacks). Introduced by commit e1153832 ("parser: Fix quadratic behavior when copying entities", 2024-01-07), first released in v2.13.0. Last unaffected release: v2.12.10. Debian trixie package is 2.12.7+dfsg+really2.9.14 (effectively v2.9.14) which predates the bug — all SAX callbacks in xmlParseReference already correctly pass ctxt->userData. Verified against the actual Debian source from salsa.debian.org. Not exploitable.
Details
References

Affected packages

Echo / libxml2

Package

Name
libxml2
Purl
pkg:deb/echo/libxml2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.12.7+dfsg+really2.9.14-2.1+deb13u2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-778a-550a-1fd5.json"