Sceawere

Vulnerability Detail

CVE-2026-76875UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PyPy pyexpat Use-After-Free Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
12h ago
Vendor
PyPy
Product
PyPy
Attack Type
Use After Free
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-29T13:17:52.280Z",
  "pubdate": "2026-09-29T13:17:52.280Z",
  "executiveSummary": "PyPy versions prior to 3.11.16 and 3.12.14 are susceptible to a critical use-after-free vulnerability within the pyexpat module.\nThe vulnerability resides in the ExternalEntityParserCreate function, which incorrectly manages memory references between parent and child XML parsers.\nBy supplying a crafted XML document, an attacker can trigger the premature deallocation of the parent parser's C structure while a child sub-parser retains a dangling pointer to it.\nThis memory corruption flaw allows for potential arbitrary code execution or application instability when libexpat attempts to dereference the freed pointer during subsequent token processing.\nThe risk is severe as it enables memory corruption via maliciously structured input. Exploitation requires the target application to utilize PyPy's XML parsing capabilities for processing untrusted content.",
  "technicalDetails": "The root cause of this vulnerability is a reference management defect within the interaction between the PyPy tracing garbage collector (GC) and the bundled libexpat library. Specifically, the ExternalEntityParserCreate function initializes a child sub-parser that maintains a raw C back-pointer to the parent parser's underlying C structure.\nIn scenarios where the parent parser's lifecycle is not explicitly extended within the PyPy heap, the GC may determine that the parent object is unreachable if the Python application fails to maintain a strong reference. Consequently, the GC proceeds to reclaim the memory associated with the parent's C structure.\nBecause the child sub-parser lacks a mechanism to notify the GC of its dependency on the parent structure—or to prevent the parent's collection—it continues to hold a pointer to the now-deallocated memory. The vulnerability is triggered during the tokenization phase: as the child parser processes the XML document, it attempts to access the parent parser's fields via the stale pointer. This constitutes a classic use-after-free condition.\nThe attack flow involves the following sequence: 1) The attacker submits a crafted XML document designed to trigger the creation of an external-entity sub-parser. 2) The application parses this document, and the parent parser object is marked for collection due to a lack of strong references in the user-level code. 3) The PyPy tracing GC executes, freeing the parent C structure. 4) The libexpat-based child parser performs a callback or internal check that references the dangling back-pointer. 5) The dereference of the freed memory occurs, leading to undefined behavior, which in the context of C-based state management, results in memory corruption.\nThis flaw affects the pyexpat module specifically. Given that libexpat is a core component for XML processing, the exposure is prevalent in any application environment utilizing PyPy that accepts external XML input. The memory corruption resulting from this dereference can be leveraged by sophisticated attackers to manipulate internal program flow, potentially leading to arbitrary code execution or significant denial-of-service conditions through segmentation faults or state corruption."
}
CVE-2026-76875: PyPy pyexpat Use-After-Free Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere