Heap Buffer Over-Read Vulnerability in Expat Library by Expat Project
CVE-2026-77214

8.3HIGH

Key Information:

Vendor

Libexpat

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-77214?

The libexpat library prior to a specific commit contains a vulnerability in the xmlparse.c file that allows for a heap buffer over-read. The issue arises when the XML_ParseBuffer function is called, which improperly advances its parsing buffer end based on an unvalidated user-supplied length. This oversight allows m_bufferEnd to exceed the bounds of the allocated buffer, leading to potential disclosure of sensitive information from adjacent heap memory, such as pointers to heap structures and function pointers. This can pose serious security risks, as it may facilitate further exploitation by revealing critical internal application structures.

Affected Version(s)

libexpat 0 <= 2.8.5

libexpat 13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fabian Wahle (Hap Security)
Filippo Tedeschi
VulnCheck
.