CVE-2026-56412
published 2026-06-21CVE-2026-56412: libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers…
PriorityP424medium5.9CVSS 3.1
AVLACLPRNUINSUCLILAL
EPSS
0.10%
1.3th percentile
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-26 | lightspeed-chatbot-rhel9 | — | — |
| ansible-automation-platform-27 | lightspeed-chatbot-rhel9 | — | — |
| debian | expat | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| libexpat_project | libexpat | < 2.8.2 | 2.8.2 |
| rhoai | odh-llama-stack-core-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-trustyai-garak-lls-provider-dsp-rhel9 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
libexpat up to 2.8.1 use after free (EUVD-2026-38189)
vuldb·2026-06-21·CVSS 4.9
CVE-2026-56412 [MEDIUM] libexpat up to 2.8.1 use after free (EUVD-2026-38189)
A vulnerability has been found in libexpat up to 2.8.1 and classified as critical. This affects an unknown part. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2026-56412. The attack requires a local approach. No exploit exists.
The affected component should be upgraded.
GHSA
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation.
ghsa_unreviewed·2026-06-21·CVSS 5.9
CVE-2026-56412 [MEDIUM] CWE-416 libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation.
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
Red Hat
libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
vendor_redhat·2026-06-21·CVSS 5.9
CVE-2026-56412 [MEDIUM] CWE-825 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
A flaw was found in libexpat. This vulnerability, present in versions before 2.8.2, stems from improper handling of XML CDATA sections, where the library fails to adequately track the depth of handler calls. This can result in a 'use-after-free' error, a type of memory corruption that could allow an attacker to crash the application or potentially gain unauthorized control.
Package: exploit-intellige
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-56412 mingw-expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-44]
bugzilla·2026-06-26·CVSS 5.9
CVE-2026-56412 [MEDIUM] CVE-2026-56412 mingw-expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-44]
CVE-2026-56412 mingw-expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-44]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-56412 expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-44]
bugzilla·2026-06-26·CVSS 5.9
CVE-2026-56412 [MEDIUM] CVE-2026-56412 expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-44]
CVE-2026-56412 expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-44]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-56412 mingw-expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-43]
bugzilla·2026-06-26·CVSS 5.9
CVE-2026-56412 [MEDIUM] CVE-2026-56412 mingw-expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-43]
CVE-2026-56412 mingw-expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-56412 expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-43]
bugzilla·2026-06-26·CVSS 5.9
CVE-2026-56412 [MEDIUM] CVE-2026-56412 expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-43]
CVE-2026-56412 expat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-56412 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
bugzilla·2026-06-21·CVSS 5.9
CVE-2026-56412 [MEDIUM] CVE-2026-56412 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
CVE-2026-56412 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
2026-06-21
Published