CVE-2024-8176
published 2025-03-14CVE-2024-8176: A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.30%
68.6th percentile
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.5_and_ipados | — | — |
| apple | ipados | — | — |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| apple | tvos | — | — |
| apple | visionos | — | — |
| apple | watchos | — | — |
| debian | expat | < expat 2.5.0-1+deb12u2 (bookworm) | expat 2.5.0-1+deb12u2 (bookworm) |
| debian | libxmltok | < expat 2.5.0-1+deb12u2 (bookworm) | expat 2.5.0-1+deb12u2 (bookworm) |
| msrc | azl3_cmake_3.30.3-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.4-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.9-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cmake_3.21.4-18_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.4-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_oracle4.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy RTU500 Product
cisa_ics·2026-03-03·CVSS 5.3
[MEDIUM] Hitachi Energy RTU500 Product
ICS Advisory
##
Hitachi Energy RTU500 Product
Release DateMarch 03, 2026
Alert CodeICSA-26-062-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Hitachi Energy is aware of vulnerabilities that affect RTU500 product versions listed in this document. Successful exploitation of these vulnerabilities can result in the exposure of low-value user management information and device outage. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
The following versions of Hitachi Energy RTU500 Product are affected:
- RTU500 series CMU Firmware vers:RTU500_series_CMU_Firmware/>=12.7.1|=13.5.1|=13.6.1|=13.7.1|<=13.7.7, 13.8.1
CVSS
Vendor
Equipment
Vulnerabilities
|
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (LibExpat) — CVE-2024-8176
vendor_oracle·2025-07-15·CVSS 4.9
CVE-2024-8176 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (LibExpat) — CVE-2024-8176
Oracle Oracle Communications Applications Risk Matrix: Core (LibExpat) vulnerability
CVE: CVE-2024-8176
CVSS: 4.9
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Apple
CVE-2025-31222: visionOS 2.5
vendor_apple·2025-05-12·CVSS 7.5
CVE-2025-31222 [HIGH] CVE-2025-31222: visionOS 2.5
Apple Security Update: About the security content of visionOS 2.5
Product: visionOS
Version: 2.5
CVE: CVE-2025-31222
Component: CVE-2024-8176
Impact: A user may be able to elevate privileges
Description: A correctness issue was addressed with improved checks.
Apple
CVE-2025-31222: tvOS 18.5
vendor_apple·2025-05-12·CVSS 7.5
CVE-2025-31222 [HIGH] CVE-2025-31222: tvOS 18.5
Apple Security Update: About the security content of tvOS 18.5
Product: tvOS
Version: 18.5
CVE: CVE-2025-31222
Component: CVE-2024-8176
Impact: A user may be able to elevate privileges
Description: A correctness issue was addressed with improved checks.
Apple
CVE-2024-8176: macOS Sequoia 15.5
vendor_apple·2025-05-12·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176: macOS Sequoia 15.5
Apple Security Update: About the security content of macOS Sequoia 15.5
Product: macOS Sequoia
Version: 15.5
CVE: CVE-2024-8176
Component: CVE-2024-8176
Apple
CVE-2025-31222: watchOS 11.5
vendor_apple·2025-05-12·CVSS 7.5
CVE-2025-31222 [HIGH] CVE-2025-31222: watchOS 11.5
Apple Security Update: About the security content of watchOS 11.5
Product: watchOS
Version: 11.5
CVE: CVE-2025-31222
Component: CVE-2024-8176
Impact: A user may be able to elevate privileges
Description: A correctness issue was addressed with improved checks.
Apple
CVE-2024-8176: iOS 18.5 and iPadOS 18.5
vendor_apple·2025-05-12·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176: iOS 18.5 and iPadOS 18.5
Apple Security Update: About the security content of iOS 18.5 and iPadOS 18.5
Product: iOS 18.5 and iPadOS
Version: 18.5
CVE: CVE-2024-8176
Component: CVE-2024-8176
Apple
CVE-2024-8176: tvOS 18.5
vendor_apple·2025-05-12·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176: tvOS 18.5
Apple Security Update: About the security content of tvOS 18.5
Product: tvOS
Version: 18.5
CVE: CVE-2024-8176
Component: CVE-2024-8176
Impact: A user may be able to elevate privileges
Description: A correctness issue was addressed with improved checks.
Apple
CVE-2024-8176: visionOS 2.5
vendor_apple·2025-05-12·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176: visionOS 2.5
Apple Security Update: About the security content of visionOS 2.5
Product: visionOS
Version: 2.5
CVE: CVE-2024-8176
Component: CVE-2024-8176
Impact: A user may be able to elevate privileges
Description: A correctness issue was addressed with improved checks.
Apple
CVE-2024-8176: macOS Ventura 13.7.6
vendor_apple·2025-05-12·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176: macOS Ventura 13.7.6
Apple Security Update: About the security content of macOS Ventura 13.7.6
Product: macOS Ventura
Version: 13.7.6
CVE: CVE-2024-8176
Component: CVE-2024-8176
Apple
CVE-2024-8176: watchOS 11.5
vendor_apple·2025-05-12·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176: watchOS 11.5
Apple Security Update: About the security content of watchOS 11.5
Product: watchOS
Version: 11.5
CVE: CVE-2024-8176
Component: CVE-2024-8176
Impact: A user may be able to elevate privileges
Description: A correctness issue was addressed with improved checks.
Apple
CVE-2024-8176: macOS Sonoma 14.7.6
vendor_apple·2025-05-12·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2024-8176
Component: CVE-2024-8176
Apple
CVE-2024-8176: iPadOS 17.7.7
vendor_apple·2025-05-12·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176: iPadOS 17.7.7
Apple Security Update: About the security content of iPadOS 17.7.7
Product: iPadOS
Version: 17.7.7
CVE: CVE-2024-8176
Component: CVE-2024-8176
Ubuntu
Expat vulnerability
vendor_ubuntu·2025-04-08
CVE-2024-8176 Expat vulnerability
Title: Expat vulnerability
Summary: Expat could be made to crash if it received specially crafted
input.
It was discovered that Expat could crash due to stack overflow when
processing XML documents with deeply nested entity references. If a user
or automated system were tricked into processing specially crafted XML
input, an attacker could use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
BSD
OpenBSD 7.5 Errata 019: SECURITY FIX
bsd_advisories·2025-03-18·CVSS 7.5
CVE-2024-8176 [HIGH] OpenBSD 7.5 Errata 019: SECURITY FIX
OpenBSD 7.5 Errata 019: SECURITY FIX
019: SECURITY FIX: March 18, 2025
All architectures In libexpat fix crash caused by stack overflow during recursion. CVE-2024-8176
Red Hat
libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat
vendor_redhat·2025-03-13·CVSS 7.5
CVE-2024-8176 [HIGH] CWE-674 libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat
libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space
Microsoft
Libexpat: expat: improper restriction of xml entity expansion depth in libexpat
vendor_msrc·2025-03-11·CVSS 7.5
CVE-2024-8176 [HIGH] CWE-674 Libexpat: expat: improper restriction of xml entity expansion depth in libexpat
Libexpat: expat: improper restriction of xml entity expansion depth in libexpat
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Debian
CVE-2024-8176: expat - A stack overflow vulnerability exists in the libexpat library due to the way it ...
vendor_debian·2024·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176: expat - A stack overflow vulnerability exists in the libexpat library due to the way it ...
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
Scope: local
bookworm: resolved (fixed in 2.5.0-1+deb12u2)
bullseye: open
forky: resolved (fixed in 2.7.0-1)
sid: resolved (fixed in 2.7.0-1)
trixie: resolved (fixed in 2.7.0-1)
GHSA
GHSA-9hcv-xw76-m4h6: A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents
ghsa_unreviewed·2025-03-14
CVE-2024-8176 [HIGH] CWE-674 GHSA-9hcv-xw76-m4h6: A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
OSV
CVE-2024-8176: A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents
osv·2025-03-14·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176: A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
No detection rules found.
No public exploits indexed.
Bugzilla
Additional security impact from expat CVE-2024-8176 / crashing other sites + whole browser
bugzilla·2025-03-20·CVSS 7.5
CVE-2024-8176 [HIGH] Additional security impact from expat CVE-2024-8176 / crashing other sites + whole browser
Additional security impact from expat CVE-2024-8176 / crashing other sites + whole browser
I had previously reported https://bugzilla.mozilla.org/show_bug.cgi?id=1954018 about expat CVE-2024-8176 that allows crashing a tab in Firefox. That bug is now public, therefore, I am reporting additional impact here in a separate bug, as I believe the security impact is significantly more severe than I initially thought.
It is possible not just to crash a tab when one controls the site displayed in the tab, but also via subresources like images (svg), iframes, or favicons (also svg). Each of them has different impacts:
* If one references a favicon with the CVE-2024-8176 proof of concept, this crashes not just the tab, but the whole browser. Apart from raising the impact of CVE-2024-8176, I also
Bugzilla
CVE-2024-8176 libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat
bugzilla·2024-09-05·CVSS 7.5
CVE-2024-8176 [HIGH] CVE-2024-8176 libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat
CVE-2024-8176 libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat
The libexpat library is vulnerable to a stack overflow due to uncontrolled recursion when processing deeply nested XML entities. This can cause the application to crash, resulting in a denial of service (DoS) or potentially leading to memory corruption, depending on the user's environment and how the library is used. The issue is triggered by supplying a specially crafted XML document designed to create a long chain of recursive entities.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:3531 https://access.redhat.com/errata/RHSA-2025:3531
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via
https://access.redhat.com/errata/RHSA-2025:13681https://access.redhat.com/errata/RHSA-2025:22033https://access.redhat.com/errata/RHSA-2025:22034https://access.redhat.com/errata/RHSA-2025:22035https://access.redhat.com/errata/RHSA-2025:22607https://access.redhat.com/errata/RHSA-2025:22785https://access.redhat.com/errata/RHSA-2025:22842https://access.redhat.com/errata/RHSA-2025:22871https://access.redhat.com/errata/RHSA-2025:3531https://access.redhat.com/errata/RHSA-2025:3734https://access.redhat.com/errata/RHSA-2025:3913https://access.redhat.com/errata/RHSA-2025:4048https://access.redhat.com/errata/RHSA-2025:4446https://access.redhat.com/errata/RHSA-2025:4447https://access.redhat.com/errata/RHSA-2025:4448https://access.redhat.com/errata/RHSA-2025:4449https://access.redhat.com/errata/RHSA-2025:7444https://access.redhat.com/errata/RHSA-2025:7512https://access.redhat.com/errata/RHSA-2025:8385https://access.redhat.com/security/cve/CVE-2024-8176https://bugzilla.redhat.com/show_bug.cgi?id=2310137https://github.com/libexpat/libexpat/issues/893https://github.com/libexpat/libexpat/pull/973http://seclists.org/fulldisclosure/2025/May/10http://seclists.org/fulldisclosure/2025/May/11http://seclists.org/fulldisclosure/2025/May/12http://seclists.org/fulldisclosure/2025/May/6http://seclists.org/fulldisclosure/2025/May/7http://seclists.org/fulldisclosure/2025/May/8http://www.openwall.com/lists/oss-security/2025/03/15/1http://www.openwall.com/lists/oss-security/2025/09/24/11https://blog.hartwork.org/posts/expat-2-7-0-released/https://bugzilla.suse.com/show_bug.cgi?id=1239618https://github.com/libexpat/libexpat/blob/R_2_7_0/expat/Changes#L40-L52https://gitlab.alpinelinux.org/alpine/aports/-/commit/d068c3ff36fc6f4789988a09c69b434db757db53https://security-tracker.debian.org/tracker/CVE-2024-8176https://security.netapp.com/advisory/ntap-20250328-0009/https://ubuntu.com/security/CVE-2024-8176https://www.kb.cert.org/vuls/id/760160
2025-03-14
Published