Executive brief
libexpat is a widely used library for processing XML data in various software applications. A vulnerability exists where the library fails to properly track the depth of internal function calls during certain error conditions. This can lead to a memory corruption issue known as a use-after-free, potentially causing the application to crash or allowing an attacker to execute unauthorized code.
Technical details
A use-after-free vulnerability exists in libexpat versions prior to 2.8.2 due to insufficient handler call depth tracking. When specific functions (XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset) are called from within handlers during a policy violation, the parser state may become inconsistent. This lack of tracking allows for memory to be accessed after it has been freed. The attack vector is local with high complexity, as it requires specific timing or conditions within the XML parsing flow to trigger the memory corruption. The issue is addressed in version 2.8.2 by introducing proper depth tracking guards.
Affected products
- libexpat project libexpat before 2.8.2
Timeline
- 2026-05-26: other: Initial pull request submitted to libexpat repository
- 2026-06-04: disclosed: CVE-2026-50219 published to NVD