CVE-2026-56132CWE-821

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there…

Medium · published June 19, 2026

CVSS v3.1
6.9
EPSS
0%
Percentile
1.3
In the wild
Unconfirmed
What it is

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

The record
Technical detail
CVSS v3.1
6.9 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
CVSS v4.0
Not supplied
EPSS
0.00108 · 1.3th percentile
Weakness
CWE-821 · Incorrect Synchronization
Published
2026-06-19T03:00Z
EPSS history
Timeline
  • 19 JUN 03:00Z
    In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there…
    cvelistv5