PT-2026-78884 · Canonical+7 · Ayttm+16
CVE-2026-76957
·
Published
2026-08-20
·
Updated
2026-09-09
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ayttm
Cableswig
Cadaver
Coin3
Expat
Gdcm
Insighttoolkit4
Libexpat
Libxmltok
Matanza
Smart
Swish-E
Tdom
Vnc4
Vtk
Wbxml2
Xmlrpc-C