CVE-2022-25236
published 2022-02-16CVE-2022-25236: xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
35.87%
98.3th percentile
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.4.5-1 (bookworm) | expat 2.4.5-1 (bookworm) |
| debian | libxmltok | < expat 2.4.5-1 (bookworm) | expat 2.4.5-1 (bookworm) |
| libexpat_project | libexpat | < 2.4.5 | 2.4.5 |
| msrc | cbl2_expat_2.4.8-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_expat_2.4.6-1_on_cbl_mariner_1.0 | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| paloalto | pan-os | — | — |
| siemens | sinema_remote_connect_server | < 3.1 | 3.1 |
| ubuntu | ayttm | — | — |
| ubuntu | coin3 | — | — |
| ubuntu | insighttoolkit | — | — |
| ubuntu | swish-e | — | — |
| ubuntu | xmlrpc-c | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable component is xmlparse.c in Expat (libexpat) before version 2.4.5; detect use of versions prior to 2.4.5 in software inventory or package managers ↗
- →The vulnerability allows insertion of namespace-separator characters into namespace URIs during XML parsing; monitor for malformed XML namespace URIs containing separator characters as anomalous input ↗
- →Expat is vendored in multiple third-party packages (XML-RPC for C/C++, ITK, Ayttm, Swish-e); scan for bundled/vendored copies of libexpat in addition to system-level packages, as system updates may not patch vendored copies ↗
- →A regression was introduced by the initial CVE-2022-25236 patch (USN-5288-1); ensure the corrected fix from USN-5320-1 is applied, not just the first patch ↗
- ·Expat is widely vendored inside third-party libraries and applications (XML-RPC for C/C++, ITK, Ayttm, Swish-e); a patched system libexpat does NOT protect against vulnerable vendored copies — each must be patched independently ↗
- ·The first patch for CVE-2022-25236 (USN-5288-1) introduced a regression; deployments that applied only the initial fix may still be broken — the corrected patch is in USN-5320-1 ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
XML-RPC for C and C++ vulnerabilities
vendor_ubuntu·2026-05-27
CVE-2022-25235 XML-RPC for C and C++ vulnerabilities
Title: XML-RPC for C and C++ vulnerabilities
Summary: Several security issues were fixed in XML-RPC for C and C++.
It was discovered that Expat, vendored in XML-RPC, incorrectly handled
certain files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ayttm vulnerabilities
vendor_ubuntu·2026-05-27
CVE-2022-25235 Ayttm vulnerabilities
Title: Ayttm vulnerabilities
Summary: Several security issues were fixed in Ayttm.
It was discovered that Expat, vendored in Ayttm, incorrectly handled
certain files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
ITK vulnerabilities
vendor_ubuntu·2026-05-07·CVSS 9.8
CVE-2022-25236 [CRITICAL] ITK vulnerabilities
Title: ITK vulnerabilities
Summary: Several security issues were fixed in ITK.
It was discovered that Expat, vendored in ITK incorrectly handled certain
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2022-25235, CVE-2022-25236)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Swish-e vulnerabilities
vendor_ubuntu·2026-05-07·CVSS 9.8
CVE-2022-25236 [CRITICAL] Swish-e vulnerabilities
Title: Swish-e vulnerabilities
Summary: Several security issues were fixed in Swish-e.
It was discovered that Expat, vendored in Swish-e incorrectly handled
certain files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code. (CVE-2022-25235, CVE-2022-25236)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Coin3D vulnerabilities
vendor_ubuntu·2026-05-07
CVE-2022-25236 Coin3D vulnerabilities
Title: Coin3D vulnerabilities
Summary: Several security issues were fixed in Coin3D.
It was discovered that Expat, vendored in Coin3D incorrectly handled
certain files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Palo Alto
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-10-29·CVSS 9.8
CVE-2019-17006 [CRITICAL] PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2019-17006 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-3518 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-25219 This CVE is fixed in PAN-OS 10.2.3, and all later versions of PAN-OS. CVE-2021-27645 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions of PAN-OS. CVE-2021-34798 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions o
CISA ICS
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
cisa_ics·2023-10-05·CVSS 8.8
[HIGH] Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
ICS Advisory
##
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
Release DateOctober 05, 2023
Alert CodeICSA-23-278-01
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: AFS65x, AFF66x, AFS67x, AFR67x Series
- Vulnerabilities: Incorrect Calculation, Integer Overflow or Wraparound, Improper Encoding or Escaping of Output, Exposure of Resource to Wrong Sphere
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities by an attacker could have a high impact on availability, integrity, and confidentiality of the targeted devices.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Hitachi Energy products and versions are affecte
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Expat) — CVE-2022-25236
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2022-25236 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Expat) — CVE-2022-25236
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Expat) vulnerability
CVE: CVE-2022-25236
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2022-07-19·CVSS 5.0
CVE-2021-46143 [MEDIUM] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, o
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2022-06-16·CVSS 3.7
[LOW] Siemens SINEMA Remote Connect Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-17
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerabilities: Multiple
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, disclose information, or allow code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- Siemens SINEMA Remote Connect Server: All v
Ubuntu
Expat vulnerabilities and regression
vendor_ubuntu·2022-03-10·CVSS 9.8
CVE-2022-25314 [CRITICAL] Expat vulnerabilities and regression
Title: Expat vulnerabilities and regression
Summary: Several security issues and a regression were fixed in Expat.
USN-5288-1 fixed several vulnerabilities in Expat. For CVE-2022-25236 it
caused a regression and an additional patch was required. This update address
this regression and several other vulnerabilities.
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-25313)
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash
or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, and Ubuntu 21.10. (CVE-2022-25314)
It was discovered that Expat incorrectly handled certain files.
An attacker cou
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2022-02-21
CVE-2022-22823 Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
vendor_redhat·2022-02-19·CVSS 9.8
CVE-2022-25236 [CRITICAL] CWE-179 expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
A flaw was found in expat. Passing one or more namespace separator characters in the "xmlns[:prefix]" attribute values made expat send malformed tag names to the XML processor on top of expat. This issue causes arbitrary code execution depending on how unexpected cases are handled inside the XML processor.
Statement: This flaw affects applications that leverage expat to parse untrusted XML files. Applications that only parse trusted XML files or do not process XML files at all are not affected by this flaw.
The xmlrpc-c component as shipped with Red Ha
Microsoft
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
vendor_msrc·2022-02-08·CVSS 9.8
CVE-2022-25236 [CRITICAL] CWE-668 xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Req
Debian
CVE-2022-25236: expat - xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert names...
vendor_debian·2022·CVSS 9.8
CVE-2022-25236 [CRITICAL] CVE-2022-25236: expat - xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert names...
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.2.10-2+deb11u2)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.5-1)
OSV
libxmltok vulnerabilities
osv·2022-07-19·CVSS 5.0
CVE-2012-1148 [MEDIUM] libxmltok vulnerabilities
libxmltok vulnerabilities
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2022-25235)
It was discovered
OSV
expat vulnerabilities and regression
osv·2022-03-10·CVSS 9.8
CVE-2022-25236 [CRITICAL] expat vulnerabilities and regression
expat vulnerabilities and regression
USN-5288-1 fixed several vulnerabilities in Expat. For CVE-2022-25236 it
caused a regression and an additional patch was required. This update address
this regression and several other vulnerabilities.
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-25313)
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash
or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, and Ubuntu 21.10. (CVE-2022-25314)
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-202
GHSA
GHSA-3c6c-gjpg-qq92: xmlparse
ghsa_unreviewed·2022-02-17
CVE-2022-25236 [CRITICAL] CWE-668 GHSA-3c6c-gjpg-qq92: xmlparse
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
OSV
CVE-2022-25236: xmlparse
osv·2022-02-16·CVSS 9.8
CVE-2022-25236 [CRITICAL] CVE-2022-25236: xmlparse
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/167238/Zoom-XMPP-Stanza-Smuggling-Remote-Code-Execution.htmlhttp://www.openwall.com/lists/oss-security/2022/02/19/1https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/561https://lists.debian.org/debian-lts-announce/2022/03/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/https://security.gentoo.org/glsa/202209-24https://security.netapp.com/advisory/ntap-20220303-0008/https://www.debian.org/security/2022/dsa-5085https://www.oracle.com/security-alerts/cpuapr2022.htmlhttp://packetstormsecurity.com/files/167238/Zoom-XMPP-Stanza-Smuggling-Remote-Code-Execution.htmlhttp://www.openwall.com/lists/oss-security/2022/02/19/1https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/561https://lists.debian.org/debian-lts-announce/2022/03/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/https://security.gentoo.org/glsa/202209-24https://security.netapp.com/advisory/ntap-20220303-0008/https://www.debian.org/security/2022/dsa-5085https://www.oracle.com/security-alerts/cpuapr2022.html
2022-02-16
Published