CVE-2026-32776: Null Pointer Dereference
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.6.4-5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32776?
CVE-2026-32776 is classified as a high severity vulnerability due to its potential to cause application crashes through NULL pointer dereferences.
How do I fix CVE-2026-32776?
To fix CVE-2026-32776, upgrade to libexpat version 2.7.5 or later.
What systems are affected by CVE-2026-32776?
CVE-2026-32776 affects libexpat versions prior to 2.7.5 on any system utilizing the library.
What type of vulnerability is CVE-2026-32776?
CVE-2026-32776 is a NULL pointer dereference vulnerability related to empty external parameter entity content.
Can CVE-2026-32776 be exploited remotely?
CVE-2026-32776 can potentially be exploited remotely if the affected software is processing untrusted input.