いやー、地味に嫌なんですけど。XMLを「通るだけの部品」と見ている組織ほど、libexpat 2.8.2未満は今日棚卸ししてほしい。CVE-2026-56403〜56407にinteger overflow、CVE-2026-56132にheap-based buffer overflow、CVE-2026-56131/56412にhandler call depth絡みのuse-after-free系が並ぶ。 単体アプリ名ではなく、OS・ミドルウェア・組込み製品・社内ツールに静かに入る波及性。SBOM、コンテナ、静的リンク、XMLを受ける入口を見て、2.8.2以上へ更新可否が必要。地味だけど、こういう基盤ライブラリは後回しが一番怖い。 #セキュリティ https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56405
Post summary
The post discloses several critical arithmetic and memory‑management flaws in libexpat 2.8.2‑minus versions and stresses the need to upgrade, without providing PoC or exploitation details.


