Bugzilla Automation <[email protected]> has asked freebsd-desktop (Team) <[email protected]> for maintainer-feedback: Bug 296191: textproc/expat2: vulnerable to e.g. CVE-2026-56408 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296191
--- Description --- See https://github.com/libexpat/libexpat/issues/1276 for brief CVE list (Release Expat 2.8.2 (no ETA) Upstream still works on patching CVEs, e.g. this one was committed just an hour ago: https://github.com/libexpat/libexpat/commit/11cd58eb92dd8eb One could either attempt backporting CVE fixes from master or wait for 2.8.2 release.
