Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY26 SECURITY RECORDS

libexpat project

libexpat

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-76957 20 Aug 2026 < 2.8.4 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-76956 20 Aug 2026 2.8.2 < 2.8.4 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-66046 18 Aug 2026 libexpat: ≤ 2.8.3 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-72522 10 Aug 2026 < 2.8.3 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-56412 21 Jun 2026 < 2.8.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56411 21 Jun 2026 < 2.8.2 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-56410 21 Jun 2026 < 2.8.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56409 21 Jun 2026 < 2.8.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56408 21 Jun 2026 < 2.8.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56407 21 Jun 2026 < 2.8.2 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-56406 21 Jun 2026 < 2.8.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56405 21 Jun 2026 < 2.8.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56404 21 Jun 2026 < 2.8.2 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-56403 21 Jun 2026 < 2.8.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-56132 19 Jun 2026 < 2.8.2 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-56131 19 Jun 2026 < 2.8.2 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Update reference ↗
CVE-2026-50219 4 Jun 2026 < 2.8.2 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2026-45186 10 May 2026 libexpat: < 2.8.1 RHSA-2026:22715: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) Update reference ↗
CVE-2026-41080 16 Apr 2026 < 2.8.0 Update to V3.1.6 or later version Update reference ↗
CVE-2026-32778 16 Mar 2026 < 2.7.5 Update to V3.1.6 or later version Update reference ↗
CVE-2026-32777 16 Mar 2026 < 2.7.5 Update to V3.1.6 or later version Update reference ↗
CVE-2026-32776 16 Mar 2026 < 2.7.5 Update to V3.1.6 or later version Update reference ↗
CVE-2026-25210 30 Jan 2026 < 2.7.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-24515 23 Jan 2026 < 2.7.4 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2025-66382 28 Nov 2025 ≤ 2.7.5 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2025-59375 15 Sep 2025 < 2.7.2 For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes You may download the oc tool and use it to inspect release image metadata for the x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:9ea794d2dd24ff7377534edfb0447e5398a28919a84300cc79fe7bb8ae550d1b All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.