CVE-2026-41401

MEDIUM

libyang - Heap Use-After-Free Write in XML Metadata Parsing

Title source: cna
STIX 2.1

Description

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-9f49-8x56-jmjc
https://github.com/CESNET/libyang/security/advisories/GHSA-9f49-8x56-jmjc
Third Party Advisory third-party-advisory
Anthropic CVD Finding ANT-2026-TZQ1KH7E
https://red.anthropic.com/2026/cvd/findings/ANT-2026-TZQ1KH7E
Third Party Advisory third-party-advisory
VulnCheck Advisory: libyang - Heap Use-After-Free Write in XML Metadata Parsing
https://www.vulncheck.com/advisories/libyang-heap-use-after-free-write-in-xml-metadata-parsing

Scores

CVSS v3 6.5
EPSS 0.0052
EPSS Percentile 39.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (2)
libyang/libyang < 5.4.3
libyang/libyang 5.4.3
Published May 26, 2026
Tracked Since May 26, 2026