CVE-2026-56406
- EPSS 0.13%
- Veröffentlicht 21.06.2026 15:48:21
- Zuletzt bearbeitet 23.06.2026 16:29:06
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-56405
- EPSS 0.13%
- Veröffentlicht 21.06.2026 15:47:13
- Zuletzt bearbeitet 23.06.2026 20:14:51
libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56404
- EPSS 0.13%
- Veröffentlicht 21.06.2026 15:45:55
- Zuletzt bearbeitet 23.06.2026 20:15:05
libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56403
- EPSS 0.13%
- Veröffentlicht 21.06.2026 15:43:55
- Zuletzt bearbeitet 23.06.2026 20:15:16
libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56132
- EPSS 0.11%
- Veröffentlicht 19.06.2026 03:00:42
- Zuletzt bearbeitet 23.06.2026 20:15:26
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-56131
- EPSS 0.14%
- Veröffentlicht 19.06.2026 02:56:36
- Zuletzt bearbeitet 23.06.2026 20:15:48
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-50219
- EPSS 0.29%
- Veröffentlicht 04.06.2026 04:20:32
- Zuletzt bearbeitet 22.07.2026 20:10:00
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVE-2026-45186
- EPSS 0.44%
- Veröffentlicht 10.05.2026 06:36:16
- Zuletzt bearbeitet 16.09.2026 13:17:58
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
CVE-2026-41080
- EPSS 0.4%
- Veröffentlicht 16.04.2026 16:52:01
- Zuletzt bearbeitet 14.07.2026 13:18:51
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVE-2026-32778
- EPSS 0.17%
- Veröffentlicht 16.03.2026 07:02:34
- Zuletzt bearbeitet 14.07.2026 13:18:49
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.