CVE-2026-77214

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨 High - libexpat Heap OOB Read in XML_ParseBuffer (CVE-2026-77214) `XML_ParseBuffer` trusts a caller-supplied length, allowing repeated oversized calls to move its buffer pointer beyond the heap allocation and read adjacent memory. This can leak pointers that weaken ASLR. Exposure requires applications using `XML_GetBuffer` / `XML_ParseBuffer` with attacker-influenced or oversized lengths. 👉 Affected: libexpat <= 2.8.5 | Fixed: 2.9.0

    0000048
    312 followersView on X

Explore more