CVE-2026-56406
published 2026-06-21CVE-2026-56406: libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
PriorityP429medium6.9CVSS 3.1
AVLACHPRNUINSUCHIHAL
EPSS
0.10%
1.1th percentile
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | — | — |
| libexpat_project | libexpat | < 2.8.2 | 2.8.2 |
CVSS provenance
nvdv3.16.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
vendor_oracle8.6HIGH
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
ghsa_unreviewed·2026-06-21
CVE-2026-56406 [MEDIUM] CWE-190 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
VulDB
libexpat up to 2.8.1 integer overflow (EUVD-2026-38183)
vuldb·2026-06-21·CVSS 6.9
CVE-2026-56406 [MEDIUM] libexpat up to 2.8.1 integer overflow (EUVD-2026-38183)
A vulnerability, which was classified as problematic, was found in libexpat up to 2.8.1. This issue affects some unknown processing. Executing a manipulation can lead to integer overflow.
This vulnerability is registered as CVE-2026-56406. The attack needs to be launched locally. No exploit is available.
You should upgrade the affected component.
Red Hat
libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
vendor_redhat·2026-06-21·CVSS 6.9
CVE-2026-56406 [MEDIUM] CWE-190 libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
A flaw was found in libexpat. An integer overflow vulnerability exists in the `XML_ParseBuffer` function due to a missing check. This flaw could allow an attacker to cause memory corruption, potentially leading to arbitrary code execution, information disclosure, or a denial of service.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: expat (Red Hat Enterprise Linux 10) - Fix defe
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Perl) — CVE-2024-56406
vendor_oracle·2026-01-15·CVSS 8.6
CVE-2024-56406 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Perl) — CVE-2024-56406
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Perl) vulnerability
CVE: CVE-2024-56406
CVSS: 8.6
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-56406 expat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer [fedora-all]
bugzilla·2026-06-23·CVSS 6.9
CVE-2026-56406 [MEDIUM] CVE-2026-56406 expat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer [fedora-all]
CVE-2026-56406 expat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-56406 libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
bugzilla·2026-06-21·CVSS 6.9
CVE-2026-56406 [MEDIUM] CVE-2026-56406 libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
CVE-2026-56406 libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
2026-06-21
Published