Skip to main content
Version: v1.2.x

CVE-2026-6653

CVE Details

Visit the official vulnerability details page for CVE-2026-6653 to learn more.

Initial Publication

06/22/2026

Last Update

07/14/2026

Third Party Dependency

libxml2

NIST CVE Summary

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

CVE Severity

9.8

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.2.1⚠️ Impacted⚠️ Impacted
1.1.8⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.