PT-2026-46147 · Libexpat+1 · Libexpat+1

·

CVE-2026-50219

·

Published

2026-06-04

·

Updated

2026-07-22

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions libexpat versions prior to 2.8.2
Description The software lacks handler call depth tracking when specific functions are called from within handlers during a policy violation. This can lead to a use-after-free condition, which occurs when a program continues to use a pointer after it has been freed. The affected functions are XML GetBuffer(), XML Parse(), XML ParseBuffer(), XML ParserFree(), and XML ParserReset().
Recommendations Update to version 2.8.2 or later.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50219
ECHO-D2DB-9152-3E07
OESA-2026-2680
RHSA-2026:30647

Affected Products

Ibm Aix
Libexpat