CVE-2022-25235
published 2022-02-16CVE-2022-25235: xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.96%
91.2th percentile
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.4.5-1 (bookworm) | expat 2.4.5-1 (bookworm) |
| debian | libxmltok | < expat 2.4.5-1 (bookworm) | expat 2.4.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libexpat_project | libexpat | < 2.4.5 | 2.4.5 |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_expat_2.4.8-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_expat_2.4.6-1_on_cbl_mariner_1.0 | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| paloalto | pan-os | — | — |
| siemens | sinema_remote_connect_server | < 3.1 | 3.1 |
| ubuntu | ayttm | — | — |
| ubuntu | coin3 | — | — |
| ubuntu | insighttoolkit | — | — |
| ubuntu | swish-e | — | — |
| ubuntu | xmlrpc-c | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libxmltok vulnerabilities
osv·2022-07-19·CVSS 5.0
CVE-2012-1148 [MEDIUM] libxmltok vulnerabilities
libxmltok vulnerabilities
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2022-25235)
It was discovered
GHSA
GHSA-8mw4-grgw-m3fp: xmltok_impl
ghsa_unreviewed·2022-02-17
CVE-2022-25235 [HIGH] CWE-116 GHSA-8mw4-grgw-m3fp: xmltok_impl
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
OSV
CVE-2022-25235: xmltok_impl
osv·2022-02-16·CVSS 9.8
CVE-2022-25235 [CRITICAL] CVE-2022-25235: xmltok_impl
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
Ubuntu
XML-RPC for C and C++ vulnerabilities
vendor_ubuntu·2026-05-27
CVE-2022-25235 XML-RPC for C and C++ vulnerabilities
Title: XML-RPC for C and C++ vulnerabilities
Summary: Several security issues were fixed in XML-RPC for C and C++.
It was discovered that Expat, vendored in XML-RPC, incorrectly handled
certain files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ayttm vulnerabilities
vendor_ubuntu·2026-05-27
CVE-2022-25235 Ayttm vulnerabilities
Title: Ayttm vulnerabilities
Summary: Several security issues were fixed in Ayttm.
It was discovered that Expat, vendored in Ayttm, incorrectly handled
certain files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
ITK vulnerabilities
vendor_ubuntu·2026-05-07·CVSS 9.8
CVE-2022-25236 [CRITICAL] ITK vulnerabilities
Title: ITK vulnerabilities
Summary: Several security issues were fixed in ITK.
It was discovered that Expat, vendored in ITK incorrectly handled certain
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2022-25235, CVE-2022-25236)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Swish-e vulnerabilities
vendor_ubuntu·2026-05-07·CVSS 9.8
CVE-2022-25236 [CRITICAL] Swish-e vulnerabilities
Title: Swish-e vulnerabilities
Summary: Several security issues were fixed in Swish-e.
It was discovered that Expat, vendored in Swish-e incorrectly handled
certain files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code. (CVE-2022-25235, CVE-2022-25236)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Coin3D vulnerabilities
vendor_ubuntu·2026-05-07
CVE-2022-25236 Coin3D vulnerabilities
Title: Coin3D vulnerabilities
Summary: Several security issues were fixed in Coin3D.
It was discovered that Expat, vendored in Coin3D incorrectly handled
certain files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Palo Alto
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-10-29·CVSS 9.8
CVE-2019-17006 [CRITICAL] PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2019-17006 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-3518 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-25219 This CVE is fixed in PAN-OS 10.2.3, and all later versions of PAN-OS. CVE-2021-27645 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions of PAN-OS. CVE-2021-34798 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions o
CISA ICS
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
cisa_ics·2023-10-05·CVSS 8.8
[HIGH] Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
ICS Advisory
##
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
Release DateOctober 05, 2023
Alert CodeICSA-23-278-01
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: AFS65x, AFF66x, AFS67x, AFR67x Series
- Vulnerabilities: Incorrect Calculation, Integer Overflow or Wraparound, Improper Encoding or Escaping of Output, Exposure of Resource to Wrong Sphere
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities by an attacker could have a high impact on availability, integrity, and confidentiality of the targeted devices.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Hitachi Energy products and versions are affecte
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2022-07-19·CVSS 5.0
CVE-2021-46143 [MEDIUM] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, o
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2022-06-16·CVSS 3.7
[LOW] Siemens SINEMA Remote Connect Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-17
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerabilities: Multiple
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, disclose information, or allow code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- Siemens SINEMA Remote Connect Server: All v
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2022-02-21
CVE-2022-22823 Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
vendor_redhat·2022-02-19·CVSS 9.8
CVE-2022-25235 [CRITICAL] CWE-838 expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
A flaw was found in expat. Passing malformed 2- and 3-byte UTF-8 sequences (for example, from start tag names) to the XML processing application on top of expat can lead to arbitrary code execution. This issue is dependent on how invalid UTF-8 is handled inside the XML processor.
Statement: This flaw affects applications that leverage expat to parse untrusted XML files. Applications that only parse trusted XML files or do not process XML files at all are not affected by this flaw.
Mitigation: There is no known mitigation other than restricti
Microsoft
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding such as checks for whether a UTF-8 character is valid in a certain context.
vendor_msrc·2022-02-08·CVSS 9.8
CVE-2022-25235 [CRITICAL] CWE-116 xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding such as checks for whether a UTF-8 character is valid in a certain context.
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding such as checks for whether a UTF-8 character is valid in a certain context.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Marin
Debian
CVE-2022-25235: expat - xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of e...
vendor_debian·2022·CVSS 9.8
CVE-2022-25235 [CRITICAL] CVE-2022-25235: expat - xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of e...
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.2.10-2+deb11u2)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.5-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2022/02/19/1https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/562https://lists.debian.org/debian-lts-announce/2022/03/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/https://security.gentoo.org/glsa/202209-24https://security.netapp.com/advisory/ntap-20220303-0008/https://www.debian.org/security/2022/dsa-5085https://www.oracle.com/security-alerts/cpuapr2022.htmlhttp://www.openwall.com/lists/oss-security/2022/02/19/1https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/562https://lists.debian.org/debian-lts-announce/2022/03/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/https://security.gentoo.org/glsa/202209-24https://security.netapp.com/advisory/ntap-20220303-0008/https://www.debian.org/security/2022/dsa-5085https://www.oracle.com/security-alerts/cpuapr2022.html
2022-02-16
Published