libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

Project Subscriptions

Vendors Products
Libyang Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 26 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
Title libyang - Heap Use-After-Free Write in XML Metadata Parsing
First Time appeared Cesnet
Cesnet libyang
Weaknesses CWE-416
CPEs cpe:2.3:a:cesnet:libyang:*:*:*:*:*:*:*:*
Vendors & Products Cesnet
Cesnet libyang
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-26T14:14:49.472Z

Reserved: 2026-04-20T14:15:22.223Z

Link: CVE-2026-41401

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-26T15:16:35.660

Modified: 2026-05-26T15:16:35.660

Link: CVE-2026-41401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T16:00:11Z

Weaknesses