PT-2026-27317 · Expat+1 · Expat+1

Titan Team

·

Published

2026-03-24

·

Updated

2026-05-05

·

CVE-2026-4739

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/S:P/AU:Y/R:U/V:C/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions InsightSoftwareConsortium ITK versions prior to 2.7.1
Description An integer overflow or wraparound condition exists in the Expat parser within the ITK software. This issue is network-reachable and allows for automatable exploitation. The vulnerability is located in the expat modules under the Modules/ThirdParty/Expat/src directory.
Recommendations Update to version 2.7.1 or later.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4739

Affected Products

Expat
Itk