Overview
What is CVE-2026-56132?
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
Vulnerability intelligence
CVE-2026-56132 and is rated Medium severity with a CVSS score of 6.9. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.