CVE-2026-56410
published 2026-06-21CVE-2026-56410: xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
PriorityP431medium6.9CVSS 3.1
AVLACHPRNUINSUCHIHAL
EPSS
0.11%
1.5th percentile
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-26 | lightspeed-chatbot-rhel9 | — | — |
| ansible-automation-platform-27 | lightspeed-chatbot-rhel9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| libexpat_project | libexpat | < 2.8.2 | 2.8.2 |
| rhoai | odh-llama-stack-core-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-trustyai-garak-lls-provider-dsp-rhel9 | — | — |
CVSS provenance
nvdv3.16.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
ghsa_unreviewed·2026-06-21
CVE-2026-56410 [MEDIUM] CWE-190 xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
VulDB
libexpat up to 2.8.1 integer overflow (EUVD-2026-38187)
vuldb·2026-06-21·CVSS 6.9
CVE-2026-56410 [MEDIUM] libexpat up to 2.8.1 integer overflow (EUVD-2026-38187)
A vulnerability was found in libexpat up to 2.8.1. It has been declared as problematic. This affects an unknown function. Such manipulation leads to integer overflow.
This vulnerability is traded as CVE-2026-56410. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
Red Hat
libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
vendor_redhat·2026-06-21·CVSS 6.9
CVE-2026-56410 [MEDIUM] CWE-190 libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
A flaw was found in libexpat. Specifically, the `xmlwf` utility contains an integer overflow vulnerability in its `resolveSystemId` function. This flaw could be exploited by an attacker to potentially gain unauthorized access to sensitive information or execute arbitrary code, leading to a compromise of the system's integrity and confidentiality.
Statement: This Moderate impact vulnerability in `libexpat`'s `xmlwf` utility, an integer overflow in `resolveSystemId`, could lead to information disclosure or arbitrary code execution. Exploitation requires local access and high attack complexity. Red Hat prod
No detection rules found.
No public exploits indexed.
2026-06-21
Published