Use-After-Free Vulnerability in libexpat Affects Multiple Versions
CVE-2026-50219

4.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2026-50219?

The libexpat library before version 2.8.2 is susceptible to a use-after-free vulnerability due to inadequate handler call depth tracking during XML processing. This issue arises when functions like XML_GetBuffer, XML_Parse, and others are invoked within handlers without proper checks, potentially leading to unexpected behaviors or exploitation through policy violations.

Affected Version(s)

libexpat 0 < 2.8.2

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.