Use-After-Free Vulnerability in PyPy's XML Parsing Module
CVE-2026-76875
6.3MEDIUM
What is CVE-2026-76875?
The pyexpat module in PyPy versions prior to 3.11.16 and 3.12.14 is affected by a use-after-free vulnerability in the ExternalEntityParserCreate function. This flaw arises when applications create external-entity sub-parsers without holding a reference to the parent parser. As a result, the child parser maintains a back-pointer to the parent, which may be freed by PyPy's garbage collector. Attackers can exploit this vulnerability by supplying a specially crafted XML document, potentially leading to memory corruption as the bundled libexpat dereferences the freed pointer during token parsing.
Affected Version(s)
PyPy 0 < 3.11.16
PyPy 3.12.0 < 3.12.14
