CVE-2026-77214
Awaiting Analysis Awaiting Analysis - Queue

Heap Buffer Over-read in libexpat XML Parser

Vulnerability report for CVE-2026-77214, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
libexpat libexpat 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-77214 is a heap buffer over-read vulnerability in libexpat before commit 13c5f63. The XML_ParseBuffer function advances the parse buffer end using an unvalidated caller-supplied length, allowing it to exceed allocated heap memory. This causes subsequent parsing to read out-of-bounds memory, potentially exposing heap pointers, libc function pointers, and code pointers to bypass ASLR and build further exploits.

Detection Guidance

To detect this vulnerability, check the version of libexpat installed on your system. Run: 'expat --version' or 'dpkg -l | grep expat' on Debian/Ubuntu or 'rpm -qa | grep expat' on RHEL/CentOS. If the version is 2.8.5 or earlier, the system is vulnerable.

Impact Analysis

This vulnerability could allow attackers to read sensitive memory contents, including pointers and code, which may lead to information disclosure, crashes, or further exploitation to bypass security mechanisms like ASLR. Applications using vulnerable libexpat versions may be affected if they process untrusted XML input.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR and HIPAA by enabling memory disclosure that may expose sensitive data. Exploiting the flaw could reveal heap pointers or code pointers, potentially leading to further attacks that compromise system integrity or confidentiality. Standards like GDPR require protection of personal data, and HIPAA mandates safeguards for protected health information; a successful exploit could violate these requirements by allowing unauthorized access to memory containing such data.

Mitigation Strategies

Immediately update libexpat to version 2.9.0 or later. Apply the patch from commit 13c5f63 or upgrade via package manager: 'apt-get update && apt-get install --only-upgrade libexpat1' or 'yum update expat'.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77214. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart