いやー、地味に嫌なんですけど。XMLを「通るだけの部品」と見ている組織ほど、libexpat 2.8.2未満は今日棚卸ししてほしい。CVE-2026-56403〜56407にinteger overflow、CVE-2026-56132にheap-based buffer overflow、CVE-2026-56131/56412にhandler call depth絡みのuse-after-free系が並ぶ。 単体アプリ名ではなく、OS・ミドルウェア・組込み製品・社内ツールに静かに入る波及性。SBOM、コンテナ、静的リンク、XMLを受ける入口を見て、2.8.2以上へ更新可否が必要。地味だけど、こういう基盤ライブラリは後回しが一番怖い。 #セキュリティ https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56405
Post summary
The tweet warns that several CVE‑2026 vulnerabilities in libexpat (before v2.8.2) include integer overflows, heap‑based buffer overflows, and use‑after‑free issues, and urges organizations to upgrade to 2.8.2 or later, referencing a Microsoft update guide for details.


