Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/libexpat/libexpat/pull/1267 |
|
Mon, 22 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Jun 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Use-After-Free in libexpat's XML_ResumeParser Call Depth Tracking |
Fri, 19 Jun 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). | |
| First Time appeared |
Libexpat Project
Libexpat Project libexpat |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libexpat Project
Libexpat Project libexpat |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-22T14:58:17.404Z
Reserved: 2026-06-19T02:56:35.597Z
Link: CVE-2026-56131
Updated: 2026-06-22T14:58:12.390Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-19T06:00:05Z