CVE-2026-76875
Received Received - Intake

Use-After-Free in PyPy Python Interpreter

Vulnerability report for CVE-2026-76875, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pypy pypy to 3.12.14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PyPy before versions 3.11.16 and 3.12.14 has a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function. Attackers can exploit this by providing a crafted XML document to applications that create external-entity sub-parsers without keeping a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser's structure, while PyPy's garbage collector may free the parent's C structure. This causes libexpat to dereference the freed pointer during token parsing, leading to memory corruption.

Detection Guidance

Detecting this vulnerability requires checking PyPy versions. Run 'pypy --version' to see if your version is below 3.11.16 or 3.12.14. If so, the system is vulnerable. Inspect applications using the pyexpat module for XML parsing with external entities.

Impact Analysis

This vulnerability could allow attackers to corrupt memory in applications using PyPy's pyexpat module with external-entity sub-parsers. This may lead to crashes, data corruption, or potential arbitrary code execution depending on the application's context and memory layout.

Mitigation Strategies

Upgrade PyPy to version 3.11.16 or later, or 3.12.14 or later. Avoid using external entities in XML parsing if upgrading is not immediately possible. Review applications for unsafe XML parsing practices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76875. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart