Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-74860
Red Hat Red Hat Enterprise Linux 10 — Libxml2: double-free/uaf in libxml2 python bindings
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H L N C H H H 8.5 .0044 35.6 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 10 unspecified 0:2.12.5-10.el10_2.4
Red Hat Enterprise Linux 8 unspecified 0:2.9.7-21.el8_10.9
Red Hat Enterprise Linux 8 unspecified 0:2.9.7-21.el8_10.9
Red Hat Enterprise Linux 9 unspecified 0:2.9.13-14.el9_8.5
Red Hat Enterprise Linux 9 unspecified 0:2.9.13-14.el9_8.5
Cert Manager support for Red Hat OpenShift release 1.20 unspecified 1790589912
Cert Manager support for Red Hat OpenShift release 1.20 unspecified 1790589914
Cert Manager support for Red Hat OpenShift release 1.20 unspecified 1790589855
Red Hat Hardened Images unspecified 2.15.4-0.1.hum1
Red Hat Enterprise Linux 10 unspecified —
+ 8 more
TIMELINE
Aug 17 Reserved by redhat
Sep 8 Published (CNA: redhat)
Sep 9 PATCH SHIPPED — CVE-2026-74860 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.15.4-0.1.hum1.
Description
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 17, 2026 | Reserved | Reserved by redhat |
| September 8, 2026 | Published | Published (CNA: redhat) |
| September 9, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-74860 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.15.4-0.1.hum1. |
Affected
Affected products and packages — 18 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | 0:2.12.5-10.el10_2.4 |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | 0:2.9.7-21.el8_10.9 |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | 0:2.9.7-21.el8_10.9 |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 0:2.9.13-14.el9_8.5 |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 0:2.9.13-14.el9_8.5 |
| Red Hat | Cert Manager support for Red Hat OpenShift release 1.20 | — | — | 1790589912 |
| Red Hat | Cert Manager support for Red Hat OpenShift release 1.20 | — | — | 1790589914 |
| Red Hat | Cert Manager support for Red Hat OpenShift release 1.20 | — | — | 1790589855 |
| Red Hat | Red Hat Hardened Images | — | — | 2.15.4-0.1.hum1 |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 6 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 7 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | — |
| Red Hat | Red Hat Hardened Images | — | — | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-74860 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.