CVE-2026-56411
published 2026-06-21CVE-2026-56411: xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
PriorityP431medium6.9CVSS 3.1
AVLACHPRNUINSUCHIHAL
EPSS
0.11%
1.5th percentile
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-26 | lightspeed-chatbot-rhel9 | — | — |
| ansible-automation-platform-27 | lightspeed-chatbot-rhel9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| libexpat_project | libexpat | < 2.8.2 | 2.8.2 |
| rhoai | odh-llama-stack-core-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-trustyai-garak-lls-provider-dsp-rhel9 | — | — |
CVSS provenance
nvdv3.16.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
ghsa_unreviewed·2026-06-21
CVE-2026-56411 [MEDIUM] CWE-190 xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
VulDB
libexpat up to 2.8.1 integer overflow (EUVD-2026-38188)
vuldb·2026-06-21·CVSS 6.9
CVE-2026-56411 [MEDIUM] libexpat up to 2.8.1 integer overflow (EUVD-2026-38188)
A vulnerability identified as problematic has been detected in libexpat up to 2.8.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2026-56411. Local access is required to approach this attack. No exploit exists.
You should upgrade the affected component.
Red Hat
expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
vendor_redhat·2026-06-21·CVSS 6.9
CVE-2026-56411 [MEDIUM] CWE-190 expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
A flaw was found in libexpat, a software library used for parsing XML (Extensible Markup Language) documents. An attacker could exploit an integer overflow vulnerability in the `xmlwf` utility by crafting malicious `NOTATION` declarations. This could lead to the disclosure of sensitive information or potentially allow the attacker to execute unauthorized code, impacting the confidentiality and integrity of data.
Package: exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 (Exploit Intelligence) - Under investigation
Package: ansible-automation-platform-26/lightspeed-chatbot-rhel
No detection rules found.
No public exploits indexed.
2026-06-21
Published