[UPDATE] [mittel] libexpat: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
Ein lokaler Angreifer kann mehrere Schwachstellen in libexpat ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Manipulation von Daten, die Umgehung von Sicherheitsmaßnahmen, die Offenlegung vertraulicher Informationen oder die Herbeiführung eines Denial-of-Service-Zustands.
CSIRTS triage
- What
- A local attacker can exploit multiple vulnerabilities in libexpat to conduct an unspecified attack, potentially including arbitrary code execution, data manipulation, bypassing security measures, disclosing confidential information, or causing a Denial of Service condition.
- Who is affected
- Users of libexpat.
- Urgency
- Remediation is medium urgency due to the wide range of potential impacts.
- Action
- Update to the latest version of libexpat to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch libexpat
Get an email when a new libexpat advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2025
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-502190.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-564030.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-564040.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-564050.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-564060.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-564070.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-564080.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-564090.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-564100.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-564110.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-50219 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56403 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56404 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56405 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56406 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56407 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56408 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56409 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56410 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56411 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56412 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownDSA-6404-1 expat - security updatedebian
- mediumCVE-2026-56405: libexpat before 2.8.2 has an integer overflow in getAttributeId.msrc
- mediumCVE-2026-56411: xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarat…msrc
- mediumCVE-2026-56407: libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue …msrc
- mediumCVE-2026-56410: xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.msrc
- mediumCVE-2026-56404: libexpat before 2.8.2 has an integer overflow in addBinding.msrc
- mediumCVE-2026-56409: xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputD…msrc
- mediumCVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse,…msrc
- mediumCVE-2026-56403: libexpat before 2.8.2 has an integer overflow in storeAtts.msrc
- mediumCVE-2026-56406: libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check tha…msrc
- mediumCVE-2026-56412: libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks ha…msrc
Recent advisories for libexpat
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- low[UPDATE] [niedrig] libexpat: Mehrere Schwachstellen ermöglichen Denial of Servicecert-bund · 2026-09-04
- mediumCVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, …nvd · 2026-08-20
- mediumCVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads …nvd · 2026-08-20
- highCVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads …msrc · 2026-08-11
- mediumCVE-2026-72522: libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrog…msrc · 2026-08-11
- mediumCVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, …msrc · 2026-08-11
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting2026-09-14
- medium[NEU] [mittel] Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten A…2026-09-14
- medium[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14
- medium[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen2026-09-14
- low[UPDATE] [niedrig] 7-Zip: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14