PT-2026-50831 · Libexpat+1 · Libexpat+1

·

CVE-2026-56131

·

Published

2026-06-19

·

Updated

2026-08-31

CVSS v3.1

6.9

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions libexpat versions prior to 2.8.2
Description An issue exists where the software lacks handler call depth tracking for calls to the XML ResumeParser() function when called from within handlers during a policy violation. This can lead to a use-after-free condition, which occurs when a program continues to use a pointer after it has been freed, potentially causing crashes or unauthorized memory access.
Recommendations Update to version 2.8.2.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90258
CVE-2026-56131
ECHO-9A07-626D-D8AE
OESA-2026-2768
OESA-2026-2769
OESA-2026-2770
OESA-2026-2857
OPENSUSE-SU-2026:11584-1
RHSA-2026:40486

Affected Products

Ibm Aix
Libexpat