CVE-2026-56412
Incomplete fix bypass in libexpat — CDATA handler depth guard missing in doCdataSection()
A patched CVE was not a closed case. Vorthix read PR #1246 as a claim, mapped every call site of the character-data handler, and found the path where the fix’s assumption silently breaks.