Integer Overflow Vulnerability in Expat Library Affecting Multiple Products
CVE-2026-56408
6.9MEDIUM
What is CVE-2026-56408?
The Expat library, specifically versions prior to 2.8.2, contains an integer overflow vulnerability within the copyString function. This can lead to potential exploitation where attackers might manipulate input sizes, resulting in unexpected behavior or program crashes. Users of affected versions are urged to update to the latest release to mitigate associated risks.
Affected Version(s)
libexpat 0 < 2.8.2
