libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Use-After-Free in libexpat Due to Missing Handler Depth Tracking for Custom Encoding Callbacks |
Thu, 20 Aug 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412. | |
| First Time appeared |
Libexpat Project
Libexpat Project libexpat |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libexpat Project
Libexpat Project libexpat |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-20T15:26:27.942Z
Reserved: 2026-08-20T04:28:04.012Z
Link: CVE-2026-76957
No data.
Status : Received
Published: 2026-08-20T05:16:29.747
Modified: 2026-08-20T16:18:30.643
Link: CVE-2026-76957
No data.
OpenCVE Enrichment
Updated: 2026-08-20T07:30:03Z