CVE-2026-56403
published 2026-06-21CVE-2026-56403: libexpat before 2.8.2 has an integer overflow in storeAtts.
PriorityP431medium6.9CVSS 3.1
AVLACHPRNUINSUCHIHAL
EPSS
0.10%
1.1th percentile
libexpat before 2.8.2 has an integer overflow in storeAtts.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-26 | lightspeed-chatbot-rhel9 | — | — |
| ansible-automation-platform-27 | lightspeed-chatbot-rhel9 | — | — |
| debian | expat | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| libexpat_project | libexpat | < 2.8.2 | 2.8.2 |
| rhoai | odh-llama-stack-core-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-trustyai-garak-lls-provider-dsp-rhel9 | — | — |
CVSS provenance
nvdv3.16.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
libexpat up to 2.8.1 integer overflow (EUVD-2026-38180)
vuldb·2026-06-21·CVSS 6.9
CVE-2026-56403 [MEDIUM] libexpat up to 2.8.1 integer overflow (EUVD-2026-38180)
A vulnerability classified as problematic has been found in libexpat up to 2.8.1. Affected by this issue is some unknown functionality. This manipulation causes integer overflow.
This vulnerability is tracked as CVE-2026-56403. The attack is restricted to local execution. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
libexpat before 2.8.2 has an integer overflow in storeAtts.
ghsa_unreviewed·2026-06-21
CVE-2026-56403 [MEDIUM] CWE-190 libexpat before 2.8.2 has an integer overflow in storeAtts.
libexpat before 2.8.2 has an integer overflow in storeAtts.
Red Hat
libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
vendor_redhat·2026-06-21·CVSS 6.9
CVE-2026-56403 [MEDIUM] CWE-190 libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts
libexpat before 2.8.2 has an integer overflow in storeAtts.
A flaw was found in libexpat. An integer overflow vulnerability exists in the `storeAtts` function. This flaw could allow an attacker to corrupt memory, leading to a denial of service, information disclosure, or potentially arbitrary code execution, compromising the integrity and confidentiality of data.
Package: exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 (Exploit Intelligence) - Under investigation
Package: ansible-automation-platform-26/lightspeed-chatbot-rhel9 (Red Hat Ansible Automation Platform 2) - Fix deferred
Package: ansible-automation-platform-27/lightspeed-chatbot-rhel9 (Red Hat Ansible Automation Platform 2) - Fix
No detection rules found.
No public exploits indexed.
2026-06-21
Published