Skip to content

build/deps: upgrade libxml2 to v2.15.2 (CVE-2026-0990)#29788

Draft
tyson-redpanda wants to merge 2 commits intodevfrom
snyk/cve-2026-0990-libxml2-2.15.2
Draft

build/deps: upgrade libxml2 to v2.15.2 (CVE-2026-0990)#29788
tyson-redpanda wants to merge 2 commits intodevfrom
snyk/cve-2026-0990-libxml2-2.15.2

Conversation

@tyson-redpanda
Copy link
Contributor

@tyson-redpanda tyson-redpanda commented Mar 10, 2026

Upgrades libxml2 from v2.14.6 to v2.15.2 to address CVE-2026-0990
(SNYK-UNMANAGED-LIBXML2-15010797): Uncontrolled Recursion via
xmlCatalogXMLResolveURI() when processing XML catalogs with
self-referencing delegate URI entries, which can cause stack exhaustion
and application crashes.

This PR depends on redpanda-data/vtools#4127 being merged first so the
artifact is available in S3.

Backports Required

  • none - not a bug fix
  • none - this is a backport
  • none - issue does not exist in previous branches
  • none - papercut/not impactful enough to backport
  • v25.3.x
  • v25.2.x
  • v25.1.x

Release Notes

Bug Fixes

  • Upgrade libxml2 to v2.15.2 to fix CVE-2026-0990 (Uncontrolled
    Recursion via xmlCatalogXMLResolveURI() in XML catalog processing).

FIXES=CORE-15341

@tyson-redpanda tyson-redpanda marked this pull request as draft March 10, 2026 19:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant