<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:44:19 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:64809 — Moderate: expat security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:64809</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: expat, AlmaLinux:8: expat-devel&lt;/p&gt;
&lt;p&gt;Expat is a C library for parsing XML documents.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking (CVE-2026-50219)
  * expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow (CVE-2026-56132)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: expat, AlmaLinux:8: expat-devel&lt;/p&gt;
&lt;p&gt;Expat is a C library for parsing XML documents.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking (CVE-2026-50219)
  * expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow (CVE-2026-56132)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:64809</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-50219</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-50219</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: expat, Alpaquita:25: expat, Alpaquita:stream: expat, BellSoft Hardened Containers:23: expat, BellSoft Hardened Containers:25: expat, BellSoft Hardened Containers:stream: expat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: expat, Alpaquita:25: expat, Alpaquita:stream: expat, BellSoft Hardened Containers:23: expat, BellSoft Hardened Containers:25: expat, BellSoft Hardened Containers:stream: expat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-50219</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1249 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</link>
      <description>certfr-2026-avi-1249</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</guid>
    </item>
    <item>
      <title>EUVD-2026-324542</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-324542</link>
      <description>EUVD-2026-324542</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-324542</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50219</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50219</link>
      <description>&lt;p&gt;libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50219</guid>
    </item>
    <item>
      <title>GHSA-v3cw-2f3g-f38x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v3cw-2f3g-f38x</link>
      <description>&lt;p&gt;libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v3cw-2f3g-f38x</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-50219 — libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Par…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-50219</link>
      <description>msrc_CVE-2026-50219</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-50219</guid>
    </item>
    <item>
      <title>OESA-2026-2680 — expat security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2680</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: expat, openEuler:22.03-LTS-SP4: expat, openEuler:24.03-LTS-SP1: expat, openEuler:24.03-LTS-SP3: expat&lt;/p&gt;
&lt;p&gt;expat is a stream-oriented XML parser library written in C. expat excels with files too large to fit RAM, and where performance and flexibility are crucial.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,(CVE-2026-50219)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: expat, openEuler:22.03-LTS-SP4: expat, openEuler:24.03-LTS-SP1: expat, openEuler:24.03-LTS-SP3: expat&lt;/p&gt;
&lt;p&gt;expat is a stream-oriented XML parser library written in C. expat excels with files too large to fit RAM, and where performance and flexibility are crucial.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,(CVE-2026-50219)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2680</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11584-1 — expat-2.8.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11584-1</link>
      <description>&lt;p&gt;expat-2.8.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat-2.8.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11584-1</guid>
    </item>
    <item>
      <title>RHSA-2026:30647 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:30647</link>
      <description>&lt;p&gt;expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:30647</guid>
    </item>
    <item>
      <title>RLSA-2026:64809 — Moderate: expat security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:64809</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: expat&lt;/p&gt;
&lt;p&gt;Expat is a C library for parsing XML documents.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking (CVE-2026-50219)&lt;/p&gt;
&lt;p&gt;* expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow (CVE-2026-56132)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: expat&lt;/p&gt;
&lt;p&gt;Expat is a C library for parsing XML documents.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking (CVE-2026-50219)&lt;/p&gt;
&lt;p&gt;* expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow (CVE-2026-56132)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:64809</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23894-1 — Security update for expat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23894-1</link>
      <description>&lt;p&gt;Security update for expat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for expat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23894-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-50219</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50219</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: expat, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:Pro:14.04:LTS: vtk, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: expat, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: cadaver, Ubuntu:Pro:16.04:LTS: coin3 and 64 more&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: expat, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:Pro:14.04:LTS: vtk, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: expat, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: cadaver, Ubuntu:Pro:16.04:LTS: coin3 and 64 more&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50219</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2025 — libexpat: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2025</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in libexpat ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Manipulation von Daten, die Umgehung von Sicherheitsmaßnahmen, die Offenlegung vertraulicher Informationen oder die Herbeiführung eines Denial-of-Service-Zustands.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in libexpat ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Manipulation von Daten, die Umgehung von Sicherheitsmaßnahmen, die Offenlegung vertraulicher Informationen oder die Herbeiführung eines Denial-of-Service-Zustands.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2025</guid>
    </item>
  </channel>
</rss>
