MEDIUMUnknown

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

CVE-2026-76957Published 2 weeks agoSource: Ubuntu

Affected packages

  • apache2
  • apr-util
  • ayttm
  • cableswig
  • cadaver
  • cmake
  • coin3
  • expat
  • firefox
  • gdcm
  • ghostscript
  • insighttoolkit4
  • libxmltok
  • matanza
  • smart
  • swish-e
  • tdom
  • texlive-bin
  • thunderbird
  • vnc4
  • vtk
  • wbxml2
  • xmlrpc-c

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412. | HackTribune