Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046.
CVSS Details
- CVSS 4.0 Base Score: 8.7 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Sep 1, 2026 | Aug 20, 2026 |
| Freebsd | — | Upgrade expat2 | Sep 2, 2026 | Sep 1, 2026 |
| Ibm Aix | — | Apply the fix or workaround for python_advisory21 | Sep 15, 2026 | Sep 15, 2026 |
| Redhat_linux | — | No solution exists | Sep 28, 2026 | Aug 20, 2026 |
| Ubuntu | — | Upgrade libexpat1Upgrade libexpat1-dev (Ubuntu Pro)Upgrade libexpat1 (Ubuntu Pro)Upgrade lib64expat1-dev (Ubuntu Pro)Upgrade expatUpgrade libexpat1-devUpgrade lib64expat1 (Ubuntu Pro)Upgrade expat (Ubuntu Pro) | Sep 24, 2026 | Aug 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub