In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
References
| Link | Resource |
|---|---|
| https://github.com/libexpat/libexpat/pull/1131 | Issue Tracking |
| https://cert-portal.siemens.com/productcert/html/ssa-253495.html |
Configurations
History
02 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary |
|
30 Jan 2026, 17:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Libexpat Project libexpat
Libexpat Project |
|
| CPE | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* | |
| References | () https://github.com/libexpat/libexpat/pull/1131 - Issue Tracking |
23 Jan 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-23 08:16
Updated : 2026-06-02 14:16
NVD link : CVE-2026-24515
Mitre link : CVE-2026-24515
CVE.ORG link : CVE-2026-24515
JSON object : View
Products Affected
libexpat_project
- libexpat
CWE
CWE-476
NULL Pointer Dereference
