{"id":"AZL-74775","summary":"CVE-2026-0989 affecting package libxml2 2.10.4-11","details":"A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested \u003cinclude\u003e directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.","modified":"2026-04-21T04:38:47.501094Z","published":"2026-01-15T15:15:52Z","upstream":["CVE-2026-0989"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0989"}],"affected":[{"package":{"name":"libxml2","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/libxml2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.10.4-11"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-74775.json"}}],"schema_version":"1.7.5"}