Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56410

Опубликовано: 21 июн. 2026
Источник: redhat
CVSS3: 6.9
EPSS Низкий

Описание

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

A flaw was found in libexpat. Specifically, the xmlwf utility contains an integer overflow vulnerability in its resolveSystemId function. This flaw could be exploited by an attacker to potentially gain unauthorized access to sensitive information or execute arbitrary code, leading to a compromise of the system's integrity and confidentiality.

Отчет

This Moderate impact vulnerability in libexpat's xmlwf utility, an integer overflow in resolveSystemId, could lead to information disclosure or arbitrary code execution. Exploitation requires local access and high attack complexity. Red Hat products that process untrusted XML input via xmlwf, including certain components of Red Hat Ansible Automation Platform and Red Hat OpenShift AI, are potentially affected.

Меры по смягчению последствий

To reduce the risk associated with this vulnerability, avoid processing untrusted or maliciously crafted XML files using the xmlwf utility. Ensure that xmlwf is only invoked with XML data from known and trusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2491181libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution.

EPSS

Процентиль: 4%
0.00139
Низкий

6.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
ubuntu
около 1 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

CVSS3: 6.9
nvd
около 1 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

CVSS3: 6.9
msrc
около 1 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

CVSS3: 6.9
debian
около 1 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSyste ...

CVSS3: 6.9
github
около 1 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

EPSS

Процентиль: 4%
0.00139
Низкий

6.9 Medium

CVSS3