Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76641.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76641.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"276563199751866197413341374821369849073",
"63215254486068534140710529667711072892",
"98475225927849785179817189837462036475",
"62204511628144875001016057423733560246",
"258048880986442864009735544404314661041",
"160790536025485591152356793249669979581",
"6787890327123429999107524848591567269",
"297276722697053780453629807845542972130"
],
"threshold": 0.9
},
"id": "CVE-2026-76641-045afb3b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf",
"target": {
"file": "expat/lib/xmlparse.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "196860208985389551831589254083440268713",
"length": 3808
},
"id": "CVE-2026-76641-47c2debd",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf",
"target": {
"file": "expat/lib/xmlparse.c",
"function": "dtdCopy"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "193420485823804263425006847397016441009",
"length": 12799
},
"id": "CVE-2026-76641-6b4e8e43",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf",
"target": {
"file": "expat/tests/basic_tests.c",
"function": "make_basic_test_case"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"166331586098571092921111335165554420856",
"47410465786597416550608233979547497167",
"244865949575798491788092291673725349749",
"56940428641862878678764736743811902632",
"76320834686356741135417404979286107483",
"24840427738563008017117376651249039280",
"201616968211034457517982453577238060994"
],
"threshold": 0.9
},
"id": "CVE-2026-76641-8a4ffde8",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf",
"target": {
"file": "expat/tests/basic_tests.c"
}
}
]
"2026-08-22T09:16:00Z"