CVE-2026-56131
published 2026-06-19CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a…
PriorityP421medium4.9CVSS 3.1
AVLACHPRNUINSUCLILAL
EPSS
0.18%
7.8th percentile
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | — | — |
| debian | xmlrpc-c | — | — |
| libexpat_project | libexpat | < 2.8.2 | 2.8.2 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
vendor_redhat·2026-08-20·CVSS 5.9
CVE-2026-76957 [MEDIUM] CWE-825 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
A flaw was found in libexpat. The library's handling of custom encoding callbacks lacks proper tracking of handler call depth, which can lead to a use-after-free vulnerability. This memory corruption flaw could allow a local attacker to cause a denial of service or potentially execute arbitrary code.
Statement: Red Hat ships libexpat (packaged as "expat") across many products. All versions of expat prior to 2.8.4 are affected by this use-after-free vulnerability. Exploitation requires trig
Red Hat
libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
vendor_redhat·2026-06-19·CVSS 5.9
CVE-2026-56131 [MEDIUM] CWE-416 libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
A use-after-free vulnerability in libexpat occurs because handler call depth isn't properly tracked when XML_ResumeParser is invoked during policy violations. This flaw can lead to information disclosure, data corruption, or denial of service.
Statement: A Moderate impact use-after-free vulnerability exists in libexpat. This flaw, requiring local access and having high attack complexity, could lead to information disclosure, data corruption, or denial of service. The need for spec
GHSA
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks.
ghsa_unreviewed·2026-08-20·CVSS 5.9
CVE-2026-76957 [MEDIUM] CWE-416 libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks.
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
GHSA
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation.
ghsa_unreviewed·2026-06-19·CVSS 5.9
CVE-2026-56131 [MEDIUM] CWE-416 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation.
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-76957 expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
bugzilla·2026-08-26·CVSS 5.9
CVE-2026-76957 [MEDIUM] CVE-2026-76957 expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
CVE-2026-76957 expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
Bugzilla
CVE-2026-76957 mingw-expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
bugzilla·2026-08-26·CVSS 5.9
CVE-2026-76957 [MEDIUM] CVE-2026-76957 mingw-expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
CVE-2026-76957 mingw-expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
Bugzilla
CVE-2026-76957 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
bugzilla·2026-08-20·CVSS 5.9
CVE-2026-76957 [MEDIUM] CVE-2026-76957 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
CVE-2026-76957 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
Bugzilla
CVE-2026-56131 mingw-expat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking [fedora-all]
bugzilla·2026-07-31·CVSS 5.9
CVE-2026-56131 [MEDIUM] CVE-2026-56131 mingw-expat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking [fedora-all]
CVE-2026-56131 mingw-expat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
Bugzilla
CVE-2026-56131 expat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking [fedora-all]
bugzilla·2026-07-31·CVSS 5.9
CVE-2026-56131 [MEDIUM] CVE-2026-56131 expat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking [fedora-all]
CVE-2026-56131 expat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
Bugzilla
CVE-2026-56131 libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
bugzilla·2026-06-19·CVSS 5.9
CVE-2026-56131 [MEDIUM] CVE-2026-56131 libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
CVE-2026-56131 libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
2026-06-19
Published