CVE-2026-76641

EUVD-2026-63493
Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
VulnCheckCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
libexpat_projectlibexpat
𝑥
≤ 2.8.3
CNA
Debian logo
Debian Releases
Debian Product
Codename
expat
bookworm
2.5.0-1+deb12u2
fixed
bookworm (security)
2.5.0-1+deb12u1
fixed
bullseye
2.2.10-2+deb11u5
fixed
bullseye (security)
2.2.10-2+deb11u7
fixed
forky
2.8.3-1
fixed
sid
2.8.3-1
fixed
trixie
2.7.1-2
fixed
trixie (security)
2.8.3-1~deb13u1
fixed