There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
{
"github_reviewed_at": "2023-07-05T21:16:34Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-416"
],
"github_reviewed": true,
"nvd_published_at": "2021-05-18T12:15:00Z"
}