CVE-2026-76875: PyPy pyexpat ExternalEntityParserCreate Use-After-Free
PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PyPyto a version that resolves this vulnerability.Fixed in 3.11.16 - Upgrade
Upgrade
PyPyto a version that resolves this vulnerability.Fixed in 3.12.14
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications running affected PyPy versions are exposed if they parse attacker-controlled XML, create external-entity sub-parsers through pyexpat's ExternalEntityParserCreate, and do not retain a reference to the parent parser.
What does an attacker need to exploit the vulnerability?
An attacker needs to supply a crafted XML document to a vulnerable application. No authentication or user interaction is required according to the supplied severity vector.
Are all pyexpat XML parsing uses affected?
No. The described condition requires use of ExternalEntityParserCreate to create an external-entity child parser without keeping the parent parser referenced; the available information does not indicate that ordinary pyexpat parsing alone is affected.
How can I determine whether my application may already be vulnerable?
Check whether it runs PyPy before 3.11.16 or 3.12.14, uses pyexpat, and calls ExternalEntityParserCreate. Review parser lifetime handling to determine whether a child external-entity parser can continue parsing after the parent parser reference is no longer retained.