CVE-2026-76641

Source
https://cve.org/CVERecord?id=CVE-2026-76641
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76641.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-76641
Downstream
Related
Published
2026-08-20T17:31:10Z
Modified
2026-09-10T18:26:47Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Expat Out-of-Bounds Read via dtdCopy
Details

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76641.json"
}
References

Affected packages

Git / github.com/libexpat/libexpat

Affected ranges

Type
GIT
Repo
https://github.com/libexpat/libexpat
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.8.3"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

Other
REC1_0
R_1_95_0
R_1_95_2
R_1_95_3
R_1_95_4
R_1_95_5
R_1_95_6
R_1_95_7
R_1_95_8
R_2_0_0
R_2_0_1
R_2_1_0
R_2_1_1
R_2_2_0
R_2_2_1
R_2_2_10
R_2_2_2
R_2_2_3
R_2_2_4
R_2_2_5
R_2_2_6
R_2_2_7
R_2_2_8
R_2_2_9
R_2_3_0
R_2_4_0
R_2_4_1
R_2_4_2
R_2_4_3
R_2_4_4
R_2_4_5
R_2_4_6
R_2_4_7
R_2_4_8
R_2_4_9
R_2_5_0
R_2_6_0
R_2_6_1
R_2_6_2
R_2_6_3
R_2_6_4
R_2_7_0
R_2_7_1
R_2_7_2
R_2_7_3
R_2_7_4
R_2_7_5
R_2_8_0
R_2_8_1
R_2_8_2
R_2_8_3
V1990307
V19981122
V19981231
V19990109
V19990425
V19990626
V19990709
V19990728
V19991013
V1_0
V1_1
V20000512
beta2
beta3
beta4
jclark-orig
libexpat-alpha-1
sourceforge_init
start

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76641.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "276563199751866197413341374821369849073",
                "63215254486068534140710529667711072892",
                "98475225927849785179817189837462036475",
                "62204511628144875001016057423733560246",
                "258048880986442864009735544404314661041",
                "160790536025485591152356793249669979581",
                "6787890327123429999107524848591567269",
                "297276722697053780453629807845542972130"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-76641-045afb3b",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf",
        "target": {
            "file": "expat/lib/xmlparse.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "196860208985389551831589254083440268713",
            "length": 3808
        },
        "id": "CVE-2026-76641-47c2debd",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf",
        "target": {
            "file": "expat/lib/xmlparse.c",
            "function": "dtdCopy"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "193420485823804263425006847397016441009",
            "length": 12799
        },
        "id": "CVE-2026-76641-6b4e8e43",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf",
        "target": {
            "file": "expat/tests/basic_tests.c",
            "function": "make_basic_test_case"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "166331586098571092921111335165554420856",
                "47410465786597416550608233979547497167",
                "244865949575798491788092291673725349749",
                "56940428641862878678764736743811902632",
                "76320834686356741135417404979286107483",
                "24840427738563008017117376651249039280",
                "201616968211034457517982453577238060994"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-76641-8a4ffde8",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf",
        "target": {
            "file": "expat/tests/basic_tests.c"
        }
    }
]
vanir_signatures_modified
"2026-08-22T09:16:00Z"