CVE-2026-76957
published 2026-08-20CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.11%
1.2th percentile
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | — | — |
| debian | xmlrpc-c | — | — |
| libexpat_project | libexpat | < 2.8.4 | 2.8.4 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks.
ghsa_unreviewed·2026-08-20·CVSS 5.9
CVE-2026-76957 [MEDIUM] CWE-416 libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks.
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
Red Hat
libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
vendor_redhat·2026-08-20·CVSS 5.9
CVE-2026-76957 [MEDIUM] CWE-825 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
A flaw was found in libexpat. The library's handling of custom encoding callbacks lacks proper tracking of handler call depth, which can lead to a use-after-free vulnerability. This memory corruption flaw could allow a local attacker to cause a denial of service or potentially execute arbitrary code.
Statement: Red Hat ships libexpat (packaged as "expat") across many products. All versions of expat prior to 2.8.4 are affected by this use-after-free vulnerability. Exploitation requires trig
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-76957 expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
bugzilla·2026-08-26·CVSS 5.9
CVE-2026-76957 [MEDIUM] CVE-2026-76957 expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
CVE-2026-76957 expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
Bugzilla
CVE-2026-76957 mingw-expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
bugzilla·2026-08-26·CVSS 5.9
CVE-2026-76957 [MEDIUM] CVE-2026-76957 mingw-expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
CVE-2026-76957 mingw-expat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
Bugzilla
CVE-2026-76957 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
bugzilla·2026-08-20·CVSS 5.9
CVE-2026-76957 [MEDIUM] CVE-2026-76957 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
CVE-2026-76957 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
2026-08-20
Published