CVE-2026-56407
published 2026-06-21CVE-2026-56407: libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
PriorityP431medium6.9CVSS 3.1
AVLACHPRNUINSUCHIHAL
EPSS
0.12%
2.5th percentile
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | — | — |
| debian | xmlrpc-c | — | — |
| libexpat_project | libexpat | < 2.8.2 | 2.8.2 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | — | — |
CVSS provenance
nvdv3.16.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libexpat: libexpat: Arbitrary code execution due to integer overflow
vendor_redhat·2026-06-21·CVSS 6.9
CVE-2026-56407 [MEDIUM] CWE-190 libexpat: libexpat: Arbitrary code execution due to integer overflow
libexpat: libexpat: Arbitrary code execution due to integer overflow
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
An integer overflow exists in libexpat's doProlog function due to improper handling of entity value lengths. A local attacker could exploit this to execute arbitrary code or access sensitive system data.
Statement: This Moderate severity flaw in libexpat, an XML parsing library, is due to an integer overflow during the processing of entity declarations. While exploitation could lead to arbitrary code execution or information disclosure, the attack requires local access and has high complexity, limiting its immediate impact on typical Red Hat deployments.
Mitigation: To prevent exploitation explicitly disab
VulDB
libexpat up to 2.8.1 integer overflow (EUVD-2026-38184)
vuldb·2026-06-21·CVSS 6.9
CVE-2026-56407 [MEDIUM] libexpat up to 2.8.1 integer overflow (EUVD-2026-38184)
A vulnerability has been found in libexpat up to 2.8.1 and classified as problematic. Impacted is an unknown function. The manipulation leads to integer overflow.
This vulnerability is documented as CVE-2026-56407. The attack needs to be performed locally. There is not any exploit available.
The affected component should be upgraded.
GHSA
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
ghsa_unreviewed·2026-06-21
CVE-2026-56407 [MEDIUM] CWE-190 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-56407 mingw-expat: libexpat: Arbitrary code execution due to integer overflow [fedora-all]
bugzilla·2026-07-29·CVSS 6.9
CVE-2026-56407 [MEDIUM] CVE-2026-56407 mingw-expat: libexpat: Arbitrary code execution due to integer overflow [fedora-all]
CVE-2026-56407 mingw-expat: libexpat: Arbitrary code execution due to integer overflow [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
Discussion:
All current releases are on mingw-expat-2.8.2.
Bugzilla
CVE-2026-56407 expat: libexpat: Arbitrary code execution due to integer overflow [fedora-all]
bugzilla·2026-07-29·CVSS 6.9
CVE-2026-56407 [MEDIUM] CVE-2026-56407 expat: libexpat: Arbitrary code execution due to integer overflow [fedora-all]
CVE-2026-56407 expat: libexpat: Arbitrary code execution due to integer overflow [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
Bugzilla
CVE-2026-56407 libexpat: libexpat: Arbitrary code execution due to integer overflow
bugzilla·2026-06-21·CVSS 6.9
CVE-2026-56407 [MEDIUM] CVE-2026-56407 libexpat: libexpat: Arbitrary code execution due to integer overflow
CVE-2026-56407 libexpat: libexpat: Arbitrary code execution due to integer overflow
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
2026-06-21
Published