CVE-2026-32778
published 2026-03-16CVE-2026-32778: libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
6.7th percentile
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | < expat 2.7.5-1 (forky) | expat 2.7.5-1 (forky) |
| libexpat_project | libexpat | < 2.7.5 | 2.7.5 |
| msrc | azl3_cmake_3.30.3-12_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.4-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.9-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cmake_3.21.4-21_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.4-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-19_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian2.9LOW
vendor_msrc2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
vendor_redhat·2026-03-16·CVSS 2.9
CVE-2026-32778 [LOW] CWE-476 libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
A flaw was found in libexpat. This vulnerability allows an attacker to trigger a NULL pointer dereference in the `setContext` function. This occurs when the system attempts to retry an operation after an out-of-memory condition, which can lead to a Denial of Service (DoS) for the affected application.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package: expat
Microsoft
CVE-2026-32778: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
vendor_msrc·2026-03-10·CVSS 2.9
CVE-2026-32778 [LOW] CWE-476 CVE-2026-32778: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Debian
CVE-2026-32778: expat - libexpat before 2.7.5 allows a NULL pointer dereference in the function setConte...
vendor_debian·2026·CVSS 2.9
CVE-2026-32778 [LOW] CVE-2026-32778: expat - libexpat before 2.7.5 allows a NULL pointer dereference in the function setConte...
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.5-1)
sid: resolved (fixed in 2.7.5-1)
trixie: open
GHSA
GHSA-hx82-g397-5ggr: libexpat before 2
ghsa_unreviewed·2026-03-16
CVE-2026-32778 [LOW] CWE-476 GHSA-hx82-g397-5ggr: libexpat before 2
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
OSV
CVE-2026-32778: libexpat before 2
osv·2026-03-16·CVSS 5.5
CVE-2026-32778 [MEDIUM] CVE-2026-32778: libexpat before 2
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-32778 libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
bugzilla·2026-03-16·CVSS 5.5
CVE-2026-32778 [MEDIUM] CVE-2026-32778 libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
CVE-2026-32778 libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Wiz
CVE-2026-32778 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.9
CVE-2026-32778 [LOW] CVE-2026-32778 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32778 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 2.9
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
thunderbird
libexpat-devel
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 19, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar
2026-03-16
Published