Expat 2.8.2 was released yesterday. The key motivation for cutting a release and doing so now was
getting security and non-security bugsfixes out to users. On the security side,
13 vulnerabilities have been fixed:
- CVE-2026-50219: missing control flow integrity checks
- CVE-2026-56131: missing control flow integrity checks
- CVE-2026-56132: out-of-bounds write
- CVE-2026-56403: integer overflow
- CVE-2026-56404: integer overflow
- CVE-2026-56405: integer overflow
- CVE-2026-56406: integer overflow
- CVE-2026-56407: integer overflow
- CVE-2026-56408: integer overflow
- CVE-2026-56409: integer overflow
- CVE-2026-56410: integer overflow
- CVE-2026-56411: integer overflow
- CVE-2026-56412: missing control flow integrity checks