OSV 1.4.0 · unreviewed · 修改于 2026-08-20 14:32
发布时间
2026-08-20 14:32
GitHub 审查时间
—
NVD 发布时间
2026-08-20 13:16
源文件
advisories/unreviewed/2026/08/GHSA-vfgp-2986-rm7g/GHSA-vfgp-2986-rm7g.json
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
该公告没有提供结构化的受影响软件包信息。