Junglewise Threat Intelligence

CVE-2026-56412: libexpat use-after-free in doCdataSection

CVE-2026-56412 · Severity: medium · CVSS 4.9 · Published 2026-06-21

Technologies: Libexpat Project Libexpat, Libexpat Project Expat. Vendors: Libexpat Project.

Executive brief

libexpat is a widely used library for parsing XML data in various software applications. A flaw in how it handles specific XML data sections could allow an attacker to cause a program crash or potentially execute unauthorized code. This issue is particularly relevant for systems processing untrusted XML files, where it could lead to service instability or data corruption.

Technical details

A use-after-free vulnerability exists in libexpat before version 2.8.2 because the doCdataSection function fails to account for XML_TOK_DATA_CHARS when tracking handler call depth. This oversight allows the isCalledFromInsideHandler() check to be bypassed during the execution of handlers within a CDATA section, effectively nullifying previous security fixes (specifically CVE-2026-50219). An attacker can exploit this by providing specially crafted XML content that triggers a policy violation, leading to memory corruption. The vulnerability is reachable locally with high complexity and no prior authentication. The issue is addressed in version 2.8.2 by wrapping character data handler calls with proper before/after handler tracking.

Affected products

  • libexpat project libexpat before 2.8.2

Timeline

  • 2026-06-20: patched: Fix merged in GitHub pull request 1278
  • 2026-06-21: disclosed: CVE published to NVD

References

Related threats