Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56411

Опубликовано: 21 июн. 2026
Источник: redhat
CVSS3: 6.9
EPSS Низкий

Описание

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

A flaw was found in libexpat, a software library used for parsing XML (Extensible Markup Language) documents. An attacker could exploit an integer overflow vulnerability in the xmlwf utility by crafting malicious NOTATION declarations. This could lead to the disclosure of sensitive information or potentially allow the attacker to execute unauthorized code, impacting the confidentiality and integrity of data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2491202expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution

EPSS

Процентиль: 4%
0.00139
Низкий

6.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
ubuntu
около 1 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

CVSS3: 6.9
nvd
около 1 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

CVSS3: 6.9
msrc
около 1 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

CVSS3: 6.9
debian
около 1 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDe ...

CVSS3: 6.9
github
около 1 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

EPSS

Процентиль: 4%
0.00139
Низкий

6.9 Medium

CVSS3