libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
Conclusion & alert: CVE-2016-9318 is rated High Exploit Risk (69.7/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.94%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +2.84% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.10% | 2.94% | +2.84% |
| 2 | 2026-05-30 | 0.15% | 0.10% | -0.05% |
| 3 | 2026-04-25 | — | 0.15% | — |
Full EPSS history (18 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2016-9318: 2 source package rows (libxml2, libxml2.13); 21 state rows across 10 repos (3.10-main, 3.11-main, 3.12-main, 3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 16, open 5. | https://security.alpinelinux.org/vuln/CVE-2016-9318 |
debian
|
not yet assigned | CVE-2016-9318 not yet assigned priority: Debian including 1 source packages (libxml2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2016-9318 |
gentoo
|
normal | CVE-2016-9318: 1 GLSA(s) (201711-01), 1 atom(s) (dev-libs/libxml2); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2016-9318 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2016-9318 |
suse
|
medium | CVE-2016-9318 severity moderate: SUSE including 48 source package names (0.9.1:libxml2-2-2.9.4-33.1, 1.0.0:libxml2-2-2.9.4-33.1, …), 154 product×package rows across 68 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (68 product lines)): Fixed 154. | https://www.suse.com/security/cve/CVE-2016-9318/ |
ubuntu
|
low | CVE-2016-9318 low priority: Ubuntu including 1 source packages (libxml2), 8 status rows across 8 suites (artful, bionic, precise, trusty, upstream, xenial, yakkety, zesty): ignored 4, released 4. | https://ubuntu.com/security/CVE-2016-9318 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| xmlsoft | libxml2 | <= 2.9.4 | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 12.04 | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* |
| canonical | ubuntu_linux | 14.04 | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 18.04 | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/94347 | Third Party Advisory VDB Entry |
| https://bugzilla.gnome.org/show_bug.cgi?id=772726 | Issue Tracking Patch Third Party Advisory VDB Entry |
| https://github.com/lsh123/xmlsec/issues/43 | Exploit Patch Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/04/msg00004.html | |
| https://security.gentoo.org/glsa/201711-01 | Third Party Advisory |
| https://usn.ubuntu.com/3739-1/ | Third Party Advisory |
| https://usn.ubuntu.com/3739-2/ | Third Party Advisory |