Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-77214— libexpat Heap Buffer Over-read in xmlparse.c via XML_ParseBuffer

Quick assessment

Affected
libexpat libexpat
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 commit 13c5f63 之前的 libexpat 版本中,xmlparse.c 存在一个堆缓冲区越界读取(heap buffer over-read)漏洞。XML_ParseBuffer 函数会使用调用者提供的长度值 len,通过执行 parser->m_bufferEnd += len 来推进解析缓冲区的结束位置。然而,该长度未经过与已分配缓冲区大小的校验,因此在重复调用 XML_ParseBuffer 时,m_bufferEnd 会超出堆分配区域的末尾,导致后续的解析操作发生越界读取。 触发此漏洞的前

CVSS 8.2 · High

Possible ATT&CK Techniques 1 AI

T1123 · Audio Capture
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77214

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
libexpat Heap Buffer Over-read in xmlparse.c via XML_ParseBuffer
Source: CVE Program / CVE List V5
Vulnerability Description
libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
libexpat libexpat 0 ~ 2.8.5 -

II. Public POCs for CVE-2026-77214

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77214

请登录查看更多情报信息。

Other References for CVE-2026-77214 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77214

No comments yet


Leave a comment