MNBSD-2026-3: expat null pointer dereference

Severity: Unknown

Affected Package: expat

Summary: expat null pointer dereference

Description

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

Affected Versions

expat

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2026-32778

Published: March 18, 2026
Last Modified: March 18, 2026