<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:38:55 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-56411</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-56411</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: expat, Alpaquita:25: expat, Alpaquita:stream: expat, BellSoft Hardened Containers:23: expat, BellSoft Hardened Containers:25: expat, BellSoft Hardened Containers:stream: expat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: expat, Alpaquita:25: expat, Alpaquita:stream: expat, BellSoft Hardened Containers:23: expat, BellSoft Hardened Containers:25: expat, BellSoft Hardened Containers:stream: expat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-56411</guid>
    </item>
    <item>
      <title>EUVD-2026-328993</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328993</link>
      <description>EUVD-2026-328993</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328993</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56411</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56411</link>
      <description>&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56411</guid>
    </item>
    <item>
      <title>GHSA-68vw-xv3c-52vp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-68vw-xv3c-52vp</link>
      <description>&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-68vw-xv3c-52vp</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-56411 — xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-56411</link>
      <description>msrc_CVE-2026-56411</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-56411</guid>
    </item>
    <item>
      <title>OESA-2026-2973 — expat security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2973</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: expat&lt;/p&gt;
&lt;p&gt;expat is a stream-oriented XML parser library written in C. expat excels with files too large to fit RAM, and where performance and flexibility are crucial.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in storeAtts.(CVE-2026-56403)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in addBinding.(CVE-2026-56404)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in getAttributeId.(CVE-2026-56405)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.(CVE-2026-56406)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.(CVE-2026-56407)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in copyString.(CVE-2026-56408)&lt;/p&gt;
&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.(CVE-2026-56409)&lt;/p&gt;
&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.(CVE-2026-56410)&lt;/p&gt;
&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.(CVE-2026-56411)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.(CVE-2026-56412)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: expat&lt;/p&gt;
&lt;p&gt;expat is a stream-oriented XML parser library written in C. expat excels with files too large to fit RAM, and where performance and flexibility are crucial.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in storeAtts.(CVE-2026-56403)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in addBinding.(CVE-2026-56404)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in getAttributeId.(CVE-2026-56405)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.(CVE-2026-56406)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.(CVE-2026-56407)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 has an integer overflow in copyString.(CVE-2026-56408)&lt;/p&gt;
&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.(CVE-2026-56409)&lt;/p&gt;
&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.(CVE-2026-56410)&lt;/p&gt;
&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.(CVE-2026-56411)&lt;/p&gt;
&lt;p&gt;libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.(CVE-2026-56412)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2973</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11584-1 — expat-2.8.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11584-1</link>
      <description>&lt;p&gt;expat-2.8.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat-2.8.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11584-1</guid>
    </item>
    <item>
      <title>RHSA-2026:65568 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:65568</link>
      <description>&lt;p&gt;expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution expat: Expat: Denial of Service via quadratic complexity in attribute processing expat: Expat: Denial of Service via XML external entity parsing libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution expat: Expat: Denial of Service via quadratic complexity in attribute processing expat: Expat: Denial of Service via XML external entity parsing libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:65568</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23894-1 — Security update for expat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23894-1</link>
      <description>&lt;p&gt;Security update for expat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for expat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23894-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-56411</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56411</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:Pro:14.04:LTS: vtk, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: cadaver, Ubuntu:Pro:16.04:LTS: coin3, Ubuntu:16.04:LTS: gdcm, Ubuntu:16.04:LTS: insighttoolkit4 and 62 more&lt;/p&gt;
&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: coin3, Ubuntu:Pro:14.04:LTS: vnc4, Ubuntu:Pro:14.04:LTS: vtk, Ubuntu:Pro:14.04:LTS: xmlrpc-c, Ubuntu:Pro:16.04:LTS: ayttm, Ubuntu:Pro:16.04:LTS: cableswig, Ubuntu:16.04:LTS: cadaver, Ubuntu:Pro:16.04:LTS: coin3, Ubuntu:16.04:LTS: gdcm, Ubuntu:16.04:LTS: insighttoolkit4 and 62 more&lt;/p&gt;
&lt;p&gt;xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56411</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2025 — libexpat: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2025</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in libexpat ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Manipulation von Daten, die Umgehung von Sicherheitsmaßnahmen, die Offenlegung vertraulicher Informationen oder die Herbeiführung eines Denial-of-Service-Zustands.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in libexpat ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Manipulation von Daten, die Umgehung von Sicherheitsmaßnahmen, die Offenlegung vertraulicher Informationen oder die Herbeiführung eines Denial-of-Service-Zustands.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2025</guid>
    </item>
  </channel>
</rss>
