NULL Pointer Dereference Vulnerability in Libexpat Affects Multiple Versions
CVE-2026-32776

4MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 March 2026

What is CVE-2026-32776?

A vulnerability exists in libexpat prior to version 2.7.5, which allows for a NULL pointer dereference when handling empty external parameter entity content. This flaw could lead to instability or crashes in applications utilizing the affected library, thus potentially disrupting services and impacting overall application performance. Users and developers are urged to update to the latest version to mitigate this issue.

Affected Version(s)

libexpat 0 < 2.7.5

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.