CVE-2026-56404
published 2026-06-21CVE-2026-56404: libexpat before 2.8.2 has an integer overflow in addBinding.
PriorityP431medium6.9CVSS 3.1
AVLACHPRNUINSUCHIHAL
EPSS
0.10%
1.1th percentile
libexpat before 2.8.2 has an integer overflow in addBinding.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| libexpat_project | libexpat | < 2.8.2 | 2.8.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
libexpat up to 2.8.1 integer overflow (EUVD-2026-38181)
vuldb·2026-06-21·CVSS 6.9
CVE-2026-56404 [MEDIUM] libexpat up to 2.8.1 integer overflow (EUVD-2026-38181)
A vulnerability classified as problematic was found in libexpat up to 2.8.1. This affects an unknown part. Such manipulation leads to integer overflow.
This vulnerability is listed as CVE-2026-56404. The attack must be carried out locally. There is no available exploit.
Upgrading the affected component is advised.
GHSA
libexpat before 2.8.2 has an integer overflow in addBinding.
ghsa_unreviewed·2026-06-21
CVE-2026-56404 [MEDIUM] CWE-190 libexpat before 2.8.2 has an integer overflow in addBinding.
libexpat before 2.8.2 has an integer overflow in addBinding.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-21
Published