A vulnerability has been found in libexpat up to 2.7.4 and classified as problematic. This affects the function setContext. The manipulation leads to null pointer dereference.

This vulnerability is documented as CVE-2026-32778. The attack needs to be performed locally. There is not any exploit available.

The affected component should be upgraded.