Update expat to version 2.8.2 (MINDBREEZE43606)

ID: MINDBREEZE43606 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 6.9 Medium 
Status: Final 
First published: September 9, 2026 
CVEs: CVE-2026-50219, CVE-2026-56131, CVE-2026-56132, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407, CVE-2026-56408, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, CVE-2026-56412 

Summary 

  • libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur 
  • libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). 
  • In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers. 
  • libexpat before 2.8.2 has an integer overflow in storeAtts. 
  • libexpat before 2.8.2 has an integer overflow in addBinding. 
  • libexpat before 2.8.2 has an integer overflow in getAttributeId. 
  • libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. 
  • libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. 
  • libexpat before 2.8.2 has an integer overflow in copyString. 
  • xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. 
  • xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. 
  • xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. 
  • libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219. 

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 26.5 Release
  • Mindbreeze InSpire SaaS 26.5 Release