CVE-2026-32776
published 2026-03-16CVE-2026-32776: libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
6.0th percentile
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | < expat 2.7.5-1 (forky) | expat 2.7.5-1 (forky) |
| libexpat_project | libexpat | < 2.7.5 | 2.7.5 |
| msrc | azl3_cmake_3.30.3-12_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.4-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.9-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cmake_3.21.4-21_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.4-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-19_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian4.0MEDIUM
vendor_msrc4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libexpat: libexpat: Denial of Service due to NULL pointer dereference
vendor_redhat·2026-03-16·CVSS 4.0
CVE-2026-32776 [MEDIUM] CWE-476 libexpat: libexpat: Denial of Service due to NULL pointer dereference
libexpat: libexpat: Denial of Service due to NULL pointer dereference
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted XML content with empty external parameter entities. This could lead to a NULL pointer dereference, causing the application to crash and resulting in a Denial of Service (DoS).
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package: expat (Red Hat Enterprise Linux 10) - Fix deferred
Package: compat-expat1 (Red
Microsoft
CVE-2026-32776: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
vendor_msrc·2026-03-10·CVSS 4.0
CVE-2026-32776 [MEDIUM] CWE-476 CVE-2026-32776: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Debian
CVE-2026-32776: expat - libexpat before 2.7.5 allows a NULL pointer dereference with empty external para...
vendor_debian·2026·CVSS 4.0
CVE-2026-32776 [MEDIUM] CVE-2026-32776: expat - libexpat before 2.7.5 allows a NULL pointer dereference with empty external para...
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.5-1)
sid: resolved (fixed in 2.7.5-1)
trixie: open
GHSA
GHSA-r8fp-cwhw-m8hh: libexpat before 2
ghsa_unreviewed·2026-03-16
CVE-2026-32776 [MEDIUM] CWE-476 GHSA-r8fp-cwhw-m8hh: libexpat before 2
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
OSV
CVE-2026-32776: libexpat before 2
osv·2026-03-16·CVSS 5.5
CVE-2026-32776 [MEDIUM] CVE-2026-32776: libexpat before 2
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-32776 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-32776 [MEDIUM] CVE-2026-32776 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32776 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libexpat-devel
firefox-debugsource
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 20, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 17, 2026
Echo Severity
Bugzilla
CVE-2026-32776 libexpat: libexpat: Denial of Service due to NULL pointer dereference
bugzilla·2026-03-16·CVSS 5.5
CVE-2026-32776 [MEDIUM] CVE-2026-32776 libexpat: libexpat: Denial of Service due to NULL pointer dereference
CVE-2026-32776 libexpat: libexpat: Denial of Service due to NULL pointer dereference
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
2026-03-16
Published