<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:30:53.815494+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-56407</id>
    <title>BELL-CVE-2026-56407</title>
    <updated>2026-10-02T16:30:54.007379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: expat, Alpaquita:25: expat, Alpaquita:stream: expat, BellSoft Hardened Containers:23: expat, BellSoft Hardened Containers:25: expat, BellSoft Hardened Containers:stream: expat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-56407"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-328944</id>
    <title>EUVD-2026-328944</title>
    <updated>2026-10-02T16:30:54.007439+00:00</updated>
    <content>EUVD-2026-328944</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-328944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56407</id>
    <title>fkie_cve-2026-56407</title>
    <updated>2026-10-02T16:30:54.007455+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-56407"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r8qx-5vfx-8w6r</id>
    <title>GHSA-r8qx-5vfx-8w6r</title>
    <updated>2026-10-02T16:30:54.007478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r8qx-5vfx-8w6r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-56407</id>
    <title>msrc_CVE-2026-56407 — libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.</title>
    <updated>2026-10-02T16:30:54.007509+00:00</updated>
    <content>msrc_CVE-2026-56407</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-56407"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2973</id>
    <title>OESA-2026-2973 — expat security update</title>
    <updated>2026-10-02T16:30:54.007538+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: expat</p>
<p>expat is a stream-oriented XML parser library written in C. expat excels with files too large to fit RAM, and where performance and flexibility are crucial.

Security Fix(es):</p>
<p>libexpat before 2.8.2 has an integer overflow in storeAtts.(CVE-2026-56403)</p>
<p>libexpat before 2.8.2 has an integer overflow in addBinding.(CVE-2026-56404)</p>
<p>libexpat before 2.8.2 has an integer overflow in getAttributeId.(CVE-2026-56405)</p>
<p>libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.(CVE-2026-56406)</p>
<p>libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.(CVE-2026-56407)</p>
<p>libexpat before 2.8.2 has an integer overflow in copyString.(CVE-2026-56408)</p>
<p>xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.(CVE-2026-56409)</p>
<p>xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.(CVE-2026-56410)</p>
<p>xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.(CVE-2026-56411)</p>
<p>libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.(CVE-2026-56412)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2973"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11584-1</id>
    <title>openSUSE-SU-2026:11584-1 — expat-2.8.2-1.1 on GA media</title>
    <updated>2026-10-02T16:30:54.007600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>expat-2.8.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11584-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:40486</id>
    <title>RHSA-2026:40486 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T16:30:54.007623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding libexpat: libexpat: Arbitrary code execution due to integer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:40486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23894-1</id>
    <title>SUSE-SU-2026:23894-1 — Security update for expat</title>
    <updated>2026-10-02T16:30:54.007642+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for expat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23894-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56407</id>
    <title>UBUNTU-CVE-2026-56407</title>
    <updated>2026-10-02T16:30:54.007664+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: expat, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:Pro:14.04:LTS: vtk, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: expat, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: cadaver, Ubuntu:Pro:16.04:LTS: coin3 and 64 more</p>
<p>libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56407"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2025</id>
    <title>WID-SEC-W-2026-2025 — libexpat: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-02T16:30:54.007806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in libexpat ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Manipulation von Daten, die Umgehung von Sicherheitsmaßnahmen, die Offenlegung vertraulicher Informationen oder die Herbeiführung eines Denial-of-Service-Zustands.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2025"/>
  </entry>
</feed>
