libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Sep 1, 2026 | Aug 20, 2026 |
| Amazon_linux_2023 | — | Upgrade firefoxUpgrade firefox-debuginfoUpgrade firefox-debugsource | Sep 1, 2026 | Aug 20, 2026 |
| Debian | — | Upgrade expat | Sep 1, 2026 | Sep 1, 2026 |
| Ibm Aix | — | Apply the fix or workaround for python_advisory21 | Sep 15, 2026 | Sep 15, 2026 |
| Redhat_linux | — | No solution exists | Aug 28, 2026 | Aug 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub