Update libexpat to version 2.7.5 (MINDBREEZE42064)
ID: MINDBREEZE42064
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS
Severity: 5.5 Medium
Status: Final
First published: August 5, 2026
CVEs: CVE-2026-32776, CVE-2026-32777, CVE-2026-32778
Summary
- CVE-2026-32776: libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
- CVE-2026-32777: libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
- CVE-2026-32778: libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Hotfix Information
Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS:
- Mindbreeze InSpire 26.3 Release
- Mindbreeze InSpire SaaS 26.3 Release