Update libexpat to version 2.7.5 (MINDBREEZE42064)

ID: MINDBREEZE42064 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 5.5 Medium 
Status: Final 
First published: August 5, 2026 
CVEs: CVE-2026-32776, CVE-2026-32777, CVE-2026-32778 

Summary 

  • CVE-2026-32776: libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content. 
  • CVE-2026-32777: libexpat before 2.7.5 allows an infinite loop while parsing DTD content. 
  • CVE-2026-32778: libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.  

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 26.3 Release
  • Mindbreeze InSpire SaaS 26.3 Release