cbcvebase.
CVE-2022-25236
published 2022-02-16

CVE-2022-25236: xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
35.87%
98.3th percentile
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianexpat< expat 2.4.5-1 (bookworm)expat 2.4.5-1 (bookworm)
debianlibxmltok< expat 2.4.5-1 (bookworm)expat 2.4.5-1 (bookworm)
libexpat_projectlibexpat< 2.4.52.4.5
msrccbl2_expat_2.4.8-1_on_cbl_mariner_2.0
msrccm1_expat_2.4.6-1_on_cbl_mariner_1.0
oraclehttp_server
oraclehttp_server
oraclezfs_storage_appliance_kit
paloaltopan-os
siemenssinema_remote_connect_server< 3.13.1
ubuntuayttm
ubuntucoin3
ubuntuinsighttoolkit
ubuntuswish-e
ubuntuxmlrpc-c

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerable component is xmlparse.c in Expat (libexpat) before version 2.4.5; detect use of versions prior to 2.4.5 in software inventory or package managers
  • The vulnerability allows insertion of namespace-separator characters into namespace URIs during XML parsing; monitor for malformed XML namespace URIs containing separator characters as anomalous input
  • Expat is vendored in multiple third-party packages (XML-RPC for C/C++, ITK, Ayttm, Swish-e); scan for bundled/vendored copies of libexpat in addition to system-level packages, as system updates may not patch vendored copies
  • A regression was introduced by the initial CVE-2022-25236 patch (USN-5288-1); ensure the corrected fix from USN-5320-1 is applied, not just the first patch
  • ·Expat is widely vendored inside third-party libraries and applications (XML-RPC for C/C++, ITK, Ayttm, Swish-e); a patched system libexpat does NOT protect against vulnerable vendored copies — each must be patched independently
  • ·The first patch for CVE-2022-25236 (USN-5288-1) introduced a regression; deployments that applied only the initial fix may still be broken — the corrected patch is in USN-5320-1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.