PT-2026-51248 · Libexpat+1 · Libexpat+1

·

CVE-2026-56412

·

Published

2026-06-21

·

Updated

2026-08-31

CVSS v3.1

6.9

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions libexpat versions prior to 2.8.2
Description An issue exists where XML TOK DATA CHARS is not considered in the doCdataSection() function. This leads to a lack of handler call depth tracking for various calls from within handlers during policy violations, which can result in a use-after-free condition. A use-after-free is a memory corruption flaw that occurs when an application continues to use a pointer after it has been freed.
Recommendations Update to version 2.8.2.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90255
CVE-2026-56412
ECHO-9D3B-357F-1F8C
OESA-2026-2973
OESA-2026-2974
OESA-2026-2975
OESA-2026-2976
OPENSUSE-SU-2026:11584-1

Affected Products

Ibm Aix
Libexpat