CVE-2026-56407
published 2026-06-21CVE-2026-56407: libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
PriorityP431medium6.9CVSS 3.1
AVLACHPRNUINSUCHIHAL
EPSS
0.10%
1.1th percentile
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| libexpat_project | libexpat | < 2.8.2 | 2.8.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
libexpat up to 2.8.1 integer overflow (EUVD-2026-38184)
vuldb·2026-06-21·CVSS 6.9
CVE-2026-56407 [MEDIUM] libexpat up to 2.8.1 integer overflow (EUVD-2026-38184)
A vulnerability has been found in libexpat up to 2.8.1 and classified as problematic. Impacted is an unknown function. The manipulation leads to integer overflow.
This vulnerability is documented as CVE-2026-56407. The attack needs to be performed locally. There is not any exploit available.
The affected component should be upgraded.
GHSA
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
ghsa_unreviewed·2026-06-21
CVE-2026-56407 [MEDIUM] CWE-190 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-21
Published