libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Jun 29, 2026 | Jun 4, 2026 |
| Amazon Linux Ami 2 | — | Upgrade firefoxUpgrade thunderbird | Jul 8, 2026 | Jul 8, 2026 |
| Amazon_linux_2023 | — | Upgrade firefox-debugsourceUpgrade firefox-debuginfoUpgrade firefox | Jul 8, 2026 | Jun 4, 2026 |
| Debian | — | Upgrade expat | Aug 2, 2026 | Aug 2, 2026 |
| Freebsd | — | Upgrade expatUpgrade linux-rl9-expatUpgrade linux-c7-expat | Jun 30, 2026 | Jun 28, 2026 |
| Ibm Aix | — | Apply the fix or workaround for python_advisory20Apply the fix or workaround for python_advisory21 | Jul 15, 2026 | Jul 14, 2026 |
| Redhat_linux | — | Upgrade expatUpgrade expat-debugsourceNo solution existsUpgrade expat-develUpgrade expat-debuginfo | Jul 17, 2026 | Jun 4, 2026 |
| Rocky_linux | — | Upgrade expat-debugsourceUpgrade expatUpgrade expat-develUpgrade expat-debuginfo | Sep 10, 2026 | Sep 9, 2026 |
| Ubuntu | — | Upgrade lib64expat1 (Ubuntu Pro)Upgrade expat (Ubuntu Pro)Upgrade libexpat1-dev (Ubuntu Pro)Upgrade libexpat1-devUpgrade expatUpgrade libexpat1 (Ubuntu Pro)Upgrade lib64expat1-dev (Ubuntu Pro)Upgrade libexpat1 | Sep 22, 2026 | Sep 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub