CVE-2026-76875 PUBLISHED

PyPy pyexpat ExternalEntityParserCreate Use-After-Free

Assigner: VulnCheck
Reserved: 19.08.2026 Published: 29.09.2026 Updated: 29.09.2026

PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor PyPy
Product PyPy
Versions Default: unaffected
  • affected from 0 to 3.11.16 (excl.)
  • affected from 3.12.0 to 3.12.14 (excl.)

Credits

  • Fabian Wahle (Hap Security) finder
  • VulnCheck coordinator

References

Problem Types

  • Use After Free CWE