PT-2026-50832 · Libexpat+1 · Libexpat+1

CVE-2026-56132

·

Published

2026-06-19

·

Updated

2026-09-08

CVSS v3.1

6.9

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions libexpat versions prior to 2.8.2
Description A heap-based buffer overflow occurs in the doProlog() function within xmlparse.c. This issue arises because the reallocation of the scaffold backing array is mishandled when data-structure sharing is utilized across multiple parsers.
Recommendations Update to version 2.8.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:64809
ALSA-2026:64810
ALSA-2026:64812
AZL-90243
CVE-2026-56132
ECHO-A065-4D1E-CE4B
OESA-2026-2768
OESA-2026-2769
OESA-2026-2770
OESA-2026-2857
OPENSUSE-SU-2026:11584-1

Affected Products

Ibm Aix
Libexpat