{"id":"CVE-2026-88385","details":"Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML input can cause text nodes allocated by mxmlNewText() to become unlinked before a parse error transfers control to the cleanup path. These orphaned nodes are not released, resulting in a persistent memory leak on each parsing attempt. Repeated attacker-controlled requests can cause cumulative memory exhaustion and denial of service.","modified":"2026-09-26T03:47:48.914565750Z","published":"2026-09-24T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88385.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88385.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88385"},{"type":"REPORT","url":"https://github.com/michaelrsweet/mxml/issues/356"},{"type":"FIX","url":"https://github.com/michaelrsweet/mxml/commit/83ef80ae3c5413b73f501edb59ee74e31ce399d0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/michaelrsweet/mxml","events":[{"introduced":"0"},{"fixed":"83ef80ae3c5413b73f501edb59ee74e31ce399d0"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v4.0.5","v4.0.4","v4.0.3","v4.0.2","v4.0.1","v4.0.0","v3.3.1","v3.3","v3.1","v3.0","v2.12","v2.11"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88385.json"}}],"schema_version":"1.9.0"}