libexpat before 2.8.4 lacks handler call depth tracking...
Moderate severity
Unreviewed
Published
Aug 20, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Aug 20, 2026
Published to the GitHub Advisory Database
Aug 20, 2026
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
References