Use-After-Free Vulnerability in Expat Library by Libexpat
CVE-2026-76957

4.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-76957?

The Expat library from Libexpat, prior to version 2.8.4, exhibits a critical vulnerability where handler call depth tracking with custom encoding callbacks is insufficient. This flaw introduces the potential for a use-after-free condition, significantly compromising the security of applications relying on this library. It is advisable for developers and organizations using the Expat library to update to the latest version immediately to mitigate any risks associated with this vulnerability.

Affected Version(s)

libexpat 0 < 2.8.4

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.