
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77214 is a buffer over-read vulnerability in libexpat's XML_ParseBuffer function affecting 32-bit platforms. On 32-bit systems, if the len parameter exceeds the unoccupied capacity of the internal parse buffer, parser->m_bufferEnd is advanced past parser->m_bufferLim, violating the internal pointer invariant (m_bufferEnd <= m_bufferLim) and causing callProcessor() to read unallocated or uninitialized heap memory. The issue is related to an integer overflow in expat_realloc and insufficient validation of the len parameter in XML_ParseBuffer. It was fixed in libexpat 2.9.0, released on October 5, 2026. The CVE status is currently Reserved, with an estimated CVSS severity of Medium (Feedly, GitHub PR #1393).
The root cause is insufficient input validation (CWE-20) in XML_ParseBuffer(): when a caller passes a len value larger than the remaining unoccupied buffer capacity (EXPAT_SAFE_PTR_DIFF(m_bufferLim, m_bufferEnd)), the parser advances m_bufferEnd past the allocated buffer limit m_bufferLim. This breaks the internal invariant m_buffer <= m_bufferPtr <= m_bufferEnd <= m_bufferLim and causes callProcessor() to read beyond the allocated heap buffer into uninitialized or unallocated memory. The issue is compounded on 32-bit platforms by an integer overflow in expat_realloc. The fix, contributed via GitHub PR #1393, adds a bounds check immediately after the parsing-state switch block for both XML_INITIALIZED and XML_PARSING states, returning XML_STATUS_ERROR with XML_ERROR_INVALID_ARGUMENT when len exceeds available buffer capacity (GitHub PR #1393, Feedly).
Successful exploitation can cause the XML parser to read unallocated or uninitialized heap memory beyond the buffer bounds, potentially exposing sensitive data from adjacent heap regions (confidentiality impact) or causing a parser crash (availability impact). The vulnerability is limited to 32-bit platforms and requires the attacker to control or influence the len argument passed to XML_ParseBuffer, or to supply a crafted XML document processed by a vulnerable application. Integrity impact is considered low, as the primary risk is out-of-bounds reads rather than writes (GitHub PR #1393, Feedly).
As of the time of this report, CVE-2026-77214 has a Reserved status with no public CVSS score assigned, no known proof-of-concept exploit code, and no evidence of in-the-wild exploitation. The vulnerability was discovered through code review and AI-assisted analysis of boundary conditions in the libexpat codebase, and was responsibly disclosed and patched prior to public CVE assignment. No EPSS score or CISA KEV catalog entry is currently available (Feedly, GitHub PR #1393).
The vulnerability is fixed in libexpat version 2.9.0, released October 5, 2026. Users and downstream distributors should upgrade to libexpat 2.9.0 or later. No configuration-based workaround is available; upgrading is the only remediation. Debian and other Linux distributions tracking this issue via OSV should apply the relevant package updates as they become available (GitHub PR #1393, Expat 2.9.0 Release).
The fix was developed collaboratively between contributor Filippo Tedeschi (filtede98) and libexpat maintainer Sebastian Pipping (hartwork) via GitHub. Pipping noted that the patch prevents the internal pointer invariant from being broken and described the validation as a sound architectural improvement. The contributor disclosed using Google's Gemini 3.8 Flash model via an agentic harness to explore the codebase and identify the boundary condition, prompting some discussion about AI-assisted vulnerability research in open source projects (GitHub PR #1393).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."