ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-76957
+1 in the same advisory: …76956
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks.

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

NVD description · AI analysis pending
7.8
group max
<1%
  • libexpat project libexpat
CVE-2026-56408
libexpat before 2.8.2 has an integer overflow in copyString.

libexpat before 2.8.2 has an integer overflow in copyString.

NVD description · AI analysis pending
6.9
group max
<1%
  • libexpat project libexpat
CVE-2026-56132
+1 in the same advisory: …56131
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there i

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

NVD description · AI analysis pending
6.9
group max
<1%
  • libexpat project libexpat