Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Use‑After‑Free in libexpat XML Parser Due to Missing Call Depth Tracking | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking |
| Weaknesses | CWE-911 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 04 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Use‑After‑Free in libexpat XML Parser Due to Missing Call Depth Tracking |
Thu, 04 Jun 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, | |
| First Time appeared |
Libexpat Project
Libexpat Project libexpat |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libexpat Project
Libexpat Project libexpat |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-04T12:36:14.744Z
Reserved: 2026-06-04T04:20:31.953Z
Link: CVE-2026-50219
Updated: 2026-06-04T12:36:11.037Z
Status : Analyzed
Published: 2026-06-04T06:16:25.050
Modified: 2026-06-04T18:39:29.530
Link: CVE-2026-50219
OpenCVE Enrichment
Updated: 2026-06-08T14:30:06Z