Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type cve · source NVD CVE
Grouped attempts with latest status; expand for attempt history.
2 attempts · first 2026-09-05T11:49:17.449983Z · last 2026-09-05T13:17:34.143984Z
Not listed in CISA KEV (local)
Types: cisa_kev
2 attempts · first 2026-09-05T11:49:17.453084Z · last 2026-09-05T13:17:34.146982Z
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow)
Types: nvd_local
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.