Heap-Based Buffer Overflow in libexpat Affects Multiple Software Products
CVE-2026-56132
6.9MEDIUM
What is CVE-2026-56132?
A vulnerability exists in libexpat prior to version 2.8.2, where a heap-based buffer overflow can occur in doProlog within xmlparse.c. This security flaw is triggered due to incorrect handling of scaffold backing array reallocation, particularly affecting data-structure sharing across different parsers. Consequently, this may lead to potential data corruption and security risks for applications utilizing libexpat.
Affected Version(s)
libexpat 0 < 2.8.2
