Protection mechanism failure in expat - CVE-2026-50219

 

Protection mechanism failure in expat - CVE-2026-50219

Published: August 19, 2026


Vulnerability identifier: #VU144338
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-50219
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to missing control flow integrity checks in XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, and XML_ParserReset when these functions are called reentrantly from bindings or callbacks. A remote attacker can trigger unsafe parser API calls to cause memory corruption.

The issue is described as relevant to language bindings.


Affected software

expat
LANTIME Operating System Firmware (LTOS)
openEuler
Anolis OS
Fedora
expat
expat-debuginfo
expat-debugsource
expat-devel
expat-help
expat-static
expat-doc
mingw-expat

How to mitigate CVE-2026-50219

Install security update from vendor's website.

expat - update to 2.8.2
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
expat - addressed in versions 2.2.9-26, 2.2.9-27, 2.2.9-28, 2.4.1-26, 2.4.1-27, 2.5.0-21, 2.5.0-22, 2.5.0-23
expat-debuginfo - addressed in versions 2.2.9-26, 2.2.9-27, 2.2.9-28, 2.4.1-26, 2.4.1-27, 2.5.0-21, 2.5.0-22, 2.5.0-23
expat-debugsource - addressed in versions 2.2.9-26, 2.2.9-27, 2.2.9-28, 2.4.1-26, 2.4.1-27, 2.5.0-21, 2.5.0-22, 2.5.0-23
expat-devel - addressed in versions 2.2.9-26, 2.2.9-27, 2.2.9-28, 2.4.1-26, 2.4.1-27, 2.5.0-21, 2.5.0-22, 2.5.0-23
expat-help - addressed in versions 2.2.9-26, 2.2.9-27, 2.2.9-28, 2.4.1-26, 2.4.1-27, 2.5.0-21, 2.5.0-22, 2.5.0-23
expat - addressed in versions 2.5.0-14, 2.5.0-16
expat-devel - addressed in versions 2.5.0-14, 2.5.0-16
expat-static - addressed in versions 2.5.0-14, 2.5.0-16
expat-doc - addressed in versions 2.5.0-14, 2.5.0-16
mingw-expat - addressed in versions 2.8.2-1.fc43, 2.8.2-1.fc44

External References

Related Security Bulletins