Skip to main content

Vendor/product archive

libexpat_project / libexpat CVEs

Beta · best-effort

61 CVEs tagged to libexpat_project / libexpat10 Critical, 19 High, 27 Medium, 5 Low, 0 Unrated.

CVE-2026-56412

Published Jun 21, 2026

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-56411

Published Jun 21, 2026

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56409

Published Jun 21, 2026

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56407

Published Jun 21, 2026

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-56406

Published Jun 21, 2026

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-56132

Published Jun 19, 2026

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sh…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-56131

Published Jun 19, 2026

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (simila…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-50219

Published Jun 4, 2026

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of…

CVSS 4.9 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-45186

Published May 10, 2026

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

CVSS 2.9 · Low
evidence mentions
14
Buzz score
51.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-41080

Published Apr 16, 2026

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

CVSS 2.9 · Low
evidence mentions
7
Buzz score
40.8
Vendor/product tagsBeta · best-effort

CVE-2026-32778

Published Mar 16, 2026

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

CVSS 2.9 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-32777

Published Mar 16, 2026

libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

CVSS 4.0 · Medium
evidence mentions
6
Buzz score
44.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-32776

Published Mar 16, 2026

libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

CVSS 4.0 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-25210

Published Jan 30, 2026

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-24515

Published Jan 23, 2026

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

CVSS 2.9 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-66382

Published Nov 28, 2025

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59375

Published Sep 15, 2025

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45492

Published Aug 30, 2024

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45491

Published Aug 30, 2024

An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 61 CVEsPage 1 of 3