Libexpat · Libexpat · CVE-2026-56131
**Name of the Vulnerable Software and Affected Versions**
libexpat versions prior to 2.8.2
**Description**
An issue exists where the software lacks handler call depth tracking for calls to the `XML ResumeParser()` function when called from within handlers during a policy violation. This can lead to a use-after-free condition, which occurs when a program continues to use a pointer after it has been freed, potentially causing crashes or unauthorized memory access.
**Recommendations**
Update to version 2.8.2.