CVE-2026-50219
published 2026-06-04CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within…
PriorityP426medium5.9CVSS 3.1
AVLACLPRNUINSUCLILAL
EPSS
0.29%
21.0th percentile
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-26 | lightspeed-chatbot-rhel9 | — | — |
| ansible-automation-platform-27 | lightspeed-chatbot-rhel9 | — | — |
| debian | expat | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| libexpat_project | libexpat | < 2.8.2 | 2.8.2 |
| rhoai | odh-llama-stack-core-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-trustyai-garak-lls-provider-dsp-rhel9 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation.
ghsa_unreviewed·2026-06-21·CVSS 5.9
CVE-2026-56412 [MEDIUM] CWE-416 libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation.
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
GHSA
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation.
ghsa_unreviewed·2026-06-19·CVSS 5.9
CVE-2026-56131 [MEDIUM] CWE-416 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation.
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
VulDB
libexpat up to 2.8.1 use after free (EUVD-2026-34206 / Nessus ID 318662)
vuldb·2026-06-05·CVSS 5.9
CVE-2026-50219 [MEDIUM] libexpat up to 2.8.1 use after free (EUVD-2026-34206 / Nessus ID 318662)
A vulnerability was found in libexpat up to 2.8.1. It has been rated as critical. Impacted is the function XML_GetBuffer/XML_Parse/XML_ParseBuffer/XML_ParserFree/XML_ParserReset. This manipulation causes use after free.
This vulnerability appears as CVE-2026-50219. The attack requires local access. There is no available exploit.
Upgrading the affected component is advised.
GHSA
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation.
ghsa_unreviewed·2026-06-04
CVE-2026-50219 [MEDIUM] CWE-416 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation.
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
Red Hat
libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
vendor_redhat·2026-06-21·CVSS 5.9
CVE-2026-56412 [MEDIUM] CWE-825 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
A flaw was found in libexpat. This vulnerability, present in versions before 2.8.2, stems from improper handling of XML CDATA sections, where the library fails to adequately track the depth of handler calls. This can result in a 'use-after-free' error, a type of memory corruption that could allow an attacker to crash the application or potentially gain unauthorized control.
Package: exploit-intellige
Red Hat
expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
vendor_redhat·2026-06-04·CVSS 5.9
CVE-2026-50219 [MEDIUM] CWE-911 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
A flaw was found in libexpat. This vulnerability occurs because the library, in versions before 2.8.2, does not properly track handler call depth when certain XML parsing functions are invoked from within handlers during a policy violation. This oversight can lead to a use-after-free condition, which may result in information disclosure, integrity loss, or denial of service.
Package: expat (Red Hat Enterprise Linux 10) - Fix deferred
Package: compat-expat1 (Red Hat En
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-56412 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
bugzilla·2026-06-21·CVSS 5.9
CVE-2026-56412 [MEDIUM] CVE-2026-56412 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
CVE-2026-56412 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
Bugzilla
CVE-2026-50219 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking [fedora-all]
bugzilla·2026-06-08·CVSS 5.9
CVE-2026-50219 [MEDIUM] CVE-2026-50219 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking [fedora-all]
CVE-2026-50219 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-50219 mingw-expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking [fedora-all]
bugzilla·2026-06-08·CVSS 5.9
CVE-2026-50219 [MEDIUM] CVE-2026-50219 mingw-expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking [fedora-all]
CVE-2026-50219 mingw-expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-50219 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
bugzilla·2026-06-04·CVSS 5.9
CVE-2026-50219 [MEDIUM] CVE-2026-50219 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
CVE-2026-50219 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
2026-06-04
Published