<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:53:41.292317+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:64809</id>
    <title>ALSA-2026:64809 — Moderate: expat security update</title>
    <updated>2026-10-02T15:53:41.570244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: expat, AlmaLinux:8: expat-devel</p>
<p>Expat is a C library for parsing XML documents.</p>
<p>Security Fix(es):</p>
<p>* expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking (CVE-2026-50219)
  * expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow (CVE-2026-56132)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:64809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-50219</id>
    <title>BELL-CVE-2026-50219</title>
    <updated>2026-10-02T15:53:41.570310+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: expat, Alpaquita:25: expat, Alpaquita:stream: expat, BellSoft Hardened Containers:23: expat, BellSoft Hardened Containers:25: expat, BellSoft Hardened Containers:stream: expat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-50219"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-324542</id>
    <title>EUVD-2026-324542</title>
    <updated>2026-10-02T15:53:41.570341+00:00</updated>
    <content>EUVD-2026-324542</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-324542"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50219</id>
    <title>fkie_cve-2026-50219</title>
    <updated>2026-10-02T15:53:41.570355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50219"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v3cw-2f3g-f38x</id>
    <title>GHSA-v3cw-2f3g-f38x</title>
    <updated>2026-10-02T15:53:41.570376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v3cw-2f3g-f38x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-50219</id>
    <title>msrc_CVE-2026-50219 — libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Par…</title>
    <updated>2026-10-02T15:53:41.570391+00:00</updated>
    <content>msrc_CVE-2026-50219</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-50219"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2680</id>
    <title>OESA-2026-2680 — expat security update</title>
    <updated>2026-10-02T15:53:41.570410+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: expat, openEuler:22.03-LTS-SP4: expat, openEuler:24.03-LTS-SP1: expat, openEuler:24.03-LTS-SP3: expat</p>
<p>expat is a stream-oriented XML parser library written in C. expat excels with files too large to fit RAM, and where performance and flexibility are crucial.

Security Fix(es):</p>
<p>libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,(CVE-2026-50219)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11584-1</id>
    <title>openSUSE-SU-2026:11584-1 — expat-2.8.2-1.1 on GA media</title>
    <updated>2026-10-02T15:53:41.570436+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>expat-2.8.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11584-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:30647</id>
    <title>RHSA-2026:30647 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T15:53:41.570461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:30647"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:64809</id>
    <title>RLSA-2026:64809 — Moderate: expat security update</title>
    <updated>2026-10-02T15:53:41.570566+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: expat</p>
<p>Expat is a C library for parsing XML documents.</p>
<p>Security Fix(es):</p>
<p>* expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking (CVE-2026-50219)</p>
<p>* expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow (CVE-2026-56132)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:64809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23894-1</id>
    <title>SUSE-SU-2026:23894-1 — Security update for expat</title>
    <updated>2026-10-02T15:53:41.570596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for expat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23894-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50219</id>
    <title>UBUNTU-CVE-2026-50219</title>
    <updated>2026-10-02T15:53:41.570622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: expat, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:Pro:14.04:LTS: vtk, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: expat, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: cadaver, Ubuntu:Pro:16.04:LTS: coin3 and 64 more</p>
<p>libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50219"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2025</id>
    <title>WID-SEC-W-2026-2025 — libexpat: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-02T15:53:41.570716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in libexpat ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Manipulation von Daten, die Umgehung von Sicherheitsmaßnahmen, die Offenlegung vertraulicher Informationen oder die Herbeiführung eines Denial-of-Service-Zustands.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2025"/>
  </entry>
</feed>
