
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4739 is an Integer Overflow or Wraparound vulnerability (CWE-190) in InsightSoftwareConsortium ITK, specifically within its bundled Expat XML parsing library (Modules/ThirdParty/Expat/src/expat). The vulnerability affects all ITK versions prior to 2.7.1 and was publicly disclosed on March 24, 2026. It carries a CVSS v4.0 base score of 9.4 (Critical), reflecting a network-accessible, low-complexity attack requiring only passive user interaction (Red Hat Advisory, Red Hat Bugzilla).
The root cause is an integer overflow or wraparound (CWE-190) in clone functions within Modules/ThirdParty/Expat/src/expat/xmlparse.c, which ITK vendors from the upstream libexpat library. This specific class of bug was originally identified in the libexpat project as CVE-2022-22822 through CVE-2022-22828 and patched upstream via commit 9f93e80; ITK's bundled copy was not updated at that time. A community contributor (npt-1707) identified the gap and submitted a patch (PR #5351) that backports the upstream fix, which was merged on August 15, 2025, and followed by a full update to expat 2.7.1 (ITK GitHub PR). The attack vector is network-based with no privileges required, and exploitation requires only passive user interaction (e.g., processing a maliciously crafted XML file).
Successful exploitation can result in arbitrary code execution or denial of service on affected systems, potentially granting an attacker full control of the host. Given ITK's use in medical imaging and scientific computing pipelines, compromise could expose sensitive research or patient data and disrupt critical workflows. The CVSS v4.0 scoring reflects high confidentiality, integrity, and availability impacts across both the vulnerable system and downstream systems (Red Hat Bugzilla, Feedly).
The EPSS score is approximately 0.042%, indicating a relatively low but non-negligible probability of exploitation in the near term. The CVSS v4.0 metadata marks exploit maturity as "ATTACKED" (active exploitation), though the Feedly executive summary notes no confirmed public proof-of-concept or verified in-the-wild exploitation evidence at time of publication. The vulnerability is automatable and requires no authentication, lowering the barrier for opportunistic attackers. No CISA KEV catalog listing has been identified, and no specific threat actor attribution is available (Feedly).
xmlparse.c clone functions within ITK's bundled Expat library — similar to techniques used against CVE-2022-22822 in upstream libexpat.The primary remediation is to upgrade ITK to version 2.7.1 or later, which includes the backported fix for the integer overflow in the bundled Expat library (xmlparse.c), merged via PR #5351 on August 15, 2025 (ITK GitHub PR). Organizations using ITK in medical imaging or scientific computing pipelines should treat this as high priority given the Critical CVSS score. As a workaround where immediate patching is not possible, restrict the sources of XML/data files processed by ITK applications to trusted, validated inputs and isolate ITK-based services from untrusted networks (Red Hat Bugzilla).
Red Hat tracked the vulnerability via its security response process (Bugzilla bug 2450592) and assigned it high priority and severity. The ENISA European Vulnerability Database (EUVD-2026-14707) also catalogued the issue. Community discussion on Ask Ubuntu raised questions about fix availability for downstream distributions. The Tenable Nessus plugin 303702 was published to detect affected installations, and Microsoft's MSRC also referenced the CVE, suggesting broad ecosystem awareness (Red Hat Advisory, Tenable).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."