libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
History

Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Libyang
Libyang libyang
Vendors & Products Libyang
Libyang libyang

Tue, 26 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
Title libyang - Heap Use-After-Free Write in XML Metadata Parsing
First Time appeared Cesnet
Cesnet libyang
Weaknesses CWE-416
CPEs cpe:2.3:a:cesnet:libyang:*:*:*:*:*:*:*:*
Vendors & Products Cesnet
Cesnet libyang
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-05-26T14:08:48.973Z

Updated: 2026-05-26T17:58:08.114Z

Reserved: 2026-04-20T14:15:22.223Z

Link: CVE-2026-41401

cve-icon Vulnrichment

Updated: 2026-05-26T17:56:42.716Z

cve-icon NVD

Status : Deferred

Published: 2026-05-26T15:16:35.660

Modified: 2026-05-26T19:47:48.987

Link: CVE-2026-41401

cve-icon Redhat

No data.