CVE-2025-59375
published 2025-09-15CVE-2025-59375: libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.28%
66.7th percentile
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.7.5_and_ipados | — | — |
| apple | ios_26.3_and_ipados | — | — |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_tahoe | — | — |
| apple | tvos | — | — |
| apple | visionos | — | — |
| apple | watchos | — | — |
| debian | expat | < expat 2.7.2-1 (forky) | expat 2.7.2-1 (forky) |
| debian | firefox | < expat 2.7.2-1 (forky) | expat 2.7.2-1 (forky) |
| debian | firefox-esr | < expat 2.7.2-1 (forky) | expat 2.7.2-1 (forky) |
| debian | thunderbird | < expat 2.7.2-1 (forky) | expat 2.7.2-1 (forky) |
| libexpat_project | libexpat | < 2.7.2 | 2.7.2 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1~deb11u1 | 1:140.9.0esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1~deb12u1 | 1:140.9.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1~deb13u1 | 1:140.9.0esr-1~deb13u1 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1 | 1:140.9.0esr-1 |
| msrc | azl3_cmake_3.30.3-9_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.4-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.4-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.9-4_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cmake_3.21.4-18_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.4-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.4-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy RTU500 Product
cisa_ics·2026-03-03·CVSS 5.3
[MEDIUM] Hitachi Energy RTU500 Product
ICS Advisory
##
Hitachi Energy RTU500 Product
Release DateMarch 03, 2026
Alert CodeICSA-26-062-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Hitachi Energy is aware of vulnerabilities that affect RTU500 product versions listed in this document. Successful exploitation of these vulnerabilities can result in the exposure of low-value user management information and device outage. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.
The following versions of Hitachi Energy RTU500 Product are affected:
- RTU500 series CMU Firmware vers:RTU500_series_CMU_Firmware/>=12.7.1|=13.5.1|=13.6.1|=13.7.1|<=13.7.7, 13.8.1
CVSS
Vendor
Equipment
Vulnerabilities
|
CISA ICS
Siemens SINEC OS
cisa_ics·2026-02-12·CVSS 9.8
[CRITICAL] Siemens SINEC OS
ICS Advisory
##
Siemens SINEC OS
Release DateFebruary 12, 2026
Alert CodeICSA-26-043-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
SINEC OS before V3.3 contains third-party components with multiple vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens SINEC OS are affected:
- RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/may_split(). This happens before the VMA lock and rmap locks are taken, which is too early. It allows racing VMA-locked page faults in the process and racing rmap walks from other processes to cause page tables to be shared again before the split occurs. This is fixed by e
Apple
CVE-2025-59375: macOS Sonoma 14.8.4
vendor_apple·2026-02-11·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-59375
Component: CVE-2025-59375
Impact: An attacker in a privileged network position may be able to intercept network traffic
Description: A logic issue was addressed with improved checks.
Apple
CVE-2025-59375: macOS Sequoia 15.7.4
vendor_apple·2026-02-11·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375: macOS Sequoia 15.7.4
Apple Security Update: About the security content of macOS Sequoia 15.7.4
Product: macOS Sequoia
Version: 15.7.4
CVE: CVE-2025-59375
Component: CVE-2025-59375
Impact: An attacker in a privileged network position may be able to intercept network traffic
Description: A logic issue was addressed with improved checks.
Apple
CVE-2025-59375: macOS Tahoe 26.3
vendor_apple·2026-02-11·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2025-59375
Component: CVE-2025-59375
Impact: An app may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
Apple
CVE-2026-20667: macOS Sonoma 14.8.4
vendor_apple·2026-02-11·CVSS 7.5
CVE-2026-20667 [HIGH] CVE-2026-20667: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20667
Component: CVE-2025-59375
Impact: An attacker in a privileged network position may be able to intercept network traffic
Description: A logic issue was addressed with improved checks.
Apple
CVE-2025-59375: iOS 26.3 and iPadOS 26.3
vendor_apple·2026-02-11·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2025-59375
Component: CVE-2025-59375
Impact: An app may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
Apple
CVE-2026-20667: macOS Tahoe 26.3
vendor_apple·2026-02-11·CVSS 7.5
CVE-2026-20667 [HIGH] CVE-2026-20667: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20667
Component: CVE-2025-59375
Impact: An app may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
Apple
CVE-2026-20667: macOS Sequoia 15.7.4
vendor_apple·2026-02-11·CVSS 7.5
CVE-2026-20667 [HIGH] CVE-2026-20667: macOS Sequoia 15.7.4
Apple Security Update: About the security content of macOS Sequoia 15.7.4
Product: macOS Sequoia
Version: 15.7.4
CVE: CVE-2026-20667
Component: CVE-2025-59375
Impact: An attacker in a privileged network position may be able to intercept network traffic
Description: A logic issue was addressed with improved checks.
Apple
CVE-2025-59375: visionOS 26.3
vendor_apple·2026-02-11·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375: visionOS 26.3
Apple Security Update: About the security content of visionOS 26.3
Product: visionOS
Version: 26.3
CVE: CVE-2025-59375
Component: CVE-2025-59375
Apple
CVE-2025-59375: iOS 18.7.5 and iPadOS 18.7.5
vendor_apple·2026-02-11·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375: iOS 18.7.5 and iPadOS 18.7.5
Apple Security Update: About the security content of iOS 18.7.5 and iPadOS 18.7.5
Product: iOS 18.7.5 and iPadOS
Version: 18.7.5
CVE: CVE-2025-59375
Component: CVE-2025-59375
Impact: An attacker in a privileged network position may be able to intercept network traffic
Description: A logic issue was addressed with improved checks.
Apple
CVE-2025-59375: watchOS 26.3
vendor_apple·2026-02-11·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375: watchOS 26.3
Apple Security Update: About the security content of watchOS 26.3
Product: watchOS
Version: 26.3
CVE: CVE-2025-59375
Component: CVE-2025-59375
Impact: An app may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
Apple
CVE-2025-59375: tvOS 26.3
vendor_apple·2026-02-11·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375: tvOS 26.3
Apple Security Update: About the security content of tvOS 26.3
Product: tvOS
Version: 26.3
CVE: CVE-2025-59375
Component: CVE-2025-59375
Apple
CVE-2026-20667: iOS 26.3 and iPadOS 26.3
vendor_apple·2026-02-11·CVSS 7.5
CVE-2026-20667 [HIGH] CVE-2026-20667: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20667
Component: CVE-2025-59375
Impact: An app may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
Apple
CVE-2026-20667: watchOS 26.3
vendor_apple·2026-02-11·CVSS 7.5
CVE-2026-20667 [HIGH] CVE-2026-20667: watchOS 26.3
Apple Security Update: About the security content of watchOS 26.3
Product: watchOS
Version: 26.3
CVE: CVE-2026-20667
Component: CVE-2025-59375
Impact: An app may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2026-02-10·CVSS 7.5
CVE-2026-24515 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
It was discovered that Expat incorrectly handled memory when parsing certain
XML files. An attacker could possibly use this issue to cause a denial of
service. This issue was only addressed in Ubuntu 25.10. (CVE-2025-59375)
It was discovered that Expat incorrectly handled the initialization of parsers
for external entities. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-24515)
It was discovered that Expat incorrectly handled integer calculations when
allocating memory for XML tags. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2026-25210)
Instructions: In general, a standard system update will make all the necess
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (LibExpat) — CVE-2025-59375
vendor_oracle·2026-01-15·CVSS 7.5
CVE-2025-59375 [HIGH] Oracle Oracle Communications Risk Matrix: Third Party (LibExpat) — CVE-2025-59375
Oracle Oracle Communications Risk Matrix: Third Party (LibExpat) vulnerability
CVE: CVE-2025-59375
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (LibExpat) — CVE-2025-59375
vendor_oracle·2025-10-15·CVSS 7.5
CVE-2025-59375 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Security (LibExpat) — CVE-2025-59375
Oracle Oracle Communications Applications Risk Matrix: Security (LibExpat) vulnerability
CVE: CVE-2025-59375
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
vendor_redhat·2025-09-15·CVSS 7.5
CVE-2025-59375 [HIGH] CWE-770 firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
A memory amplification vulnerability in libexpat allows attackers to trigger excessive dynamic memory allocations by submitting specially crafted XML input. A small input (~250 KiB) can cause the parser to allocate hundreds of megabytes, leading to denial-of-service (DoS) through memory exhaustion.
Statement: This issue is Important rather than Critical because, while it allows for significant resource exhaustion leading to denial-of-service (DoS), it does not enable arbitrary code executi
Microsoft
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
vendor_msrc·2025-09-09·CVSS 7.5
CVE-2025-59375 [HIGH] CWE-770 libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Cu
Debian
CVE-2025-59375: expat - libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory ...
vendor_debian·2025·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375: expat - libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory ...
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.2-1)
sid: resolved (fixed in 2.7.2-1)
trixie: open
Mozilla
Mozilla Foundation Security Advisory 2026-24: CVE-2025-59375
vendor_mozilla·CVSS 7.5
CVE-2025-59375 [HIGH] Mozilla Foundation Security Advisory 2026-24: CVE-2025-59375
Mozilla Foundation Security Advisory 2026-24
CVE: CVE-2025-59375
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.9
Mozilla
Mozilla Foundation Security Advisory 2026-20: CVE-2025-59375
vendor_mozilla·CVSS 7.5
CVE-2025-59375 [HIGH] Mozilla Foundation Security Advisory 2026-20: CVE-2025-59375
Mozilla Foundation Security Advisory 2026-20
CVE: CVE-2025-59375
Product: Firefox
Impact: high
Fixed in: Firefox 149
Mozilla
Mozilla Foundation Security Advisory 2026-22: CVE-2025-59375
vendor_mozilla·CVSS 7.5
CVE-2025-59375 [HIGH] Mozilla Foundation Security Advisory 2026-22: CVE-2025-59375
Mozilla Foundation Security Advisory 2026-22
CVE: CVE-2025-59375
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.9
Mozilla
Mozilla Foundation Security Advisory 2026-23: CVE-2025-59375
vendor_mozilla·CVSS 7.5
CVE-2025-59375 [HIGH] Mozilla Foundation Security Advisory 2026-23: CVE-2025-59375
Mozilla Foundation Security Advisory 2026-23
CVE: CVE-2025-59375
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 149
OSV
expat vulnerabilities
osv·2026-02-10·CVSS 7.5
CVE-2025-59375 [HIGH] expat vulnerabilities
expat vulnerabilities
It was discovered that Expat incorrectly handled memory when parsing certain
XML files. An attacker could possibly use this issue to cause a denial of
service. This issue was only addressed in Ubuntu 25.10. (CVE-2025-59375)
It was discovered that Expat incorrectly handled the initialization of parsers
for external entities. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-24515)
It was discovered that Expat incorrectly handled integer calculations when
allocating memory for XML tags. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2026-25210)
GHSA
GHSA-vjqp-pjp6-xcxx: libexpat in Expat before 2
ghsa_unreviewed·2025-09-15
CVE-2025-59375 [HIGH] CWE-770 GHSA-vjqp-pjp6-xcxx: libexpat in Expat before 2
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
OSV
CVE-2025-59375: libexpat in Expat before 2
osv·2025-09-15·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375: libexpat in Expat before 2
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-59375 libexpat before 2.7.2 allows attackers to trigger large dynamic memory allocations via parsing a small document
bugzilla·2025-09-15·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375 libexpat before 2.7.2 allows attackers to trigger large dynamic memory allocations via parsing a small document
CVE-2025-59375 libexpat before 2.7.2 allows attackers to trigger large dynamic memory allocations via parsing a small document
This could hit us: https://cvefeed.io/vuln/detail/CVE-2025-59375
Relevant changes: https://github.com/libexpat/libexpat/pull/1034/files
Discussion:
Hi Andrew/Henri, can you please audit/assess the impact on us? Thanks.
---
The impact of this should be relatively low in the context of the web browser: You can use a lot of memory with very few lines of JavaScript. We do not protect against large allocations (or am I missing something?)
---
I agree with Freddy: There are various ways for Web content to make a content process run out of memory, so in that sense this is just one more case (of expat's RLBox sandbox running out of memory). It seems to me that we sh
Bugzilla
CVE-2025-59375 firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
bugzilla·2025-09-15·CVSS 7.5
CVE-2025-59375 [HIGH] CVE-2025-59375 firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
CVE-2025-59375 firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Core Services 2.4.62.SP2
Via RHSA-2025:19020 https://access.redhat.com/errata/RHSA-2025:19020
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:19403 https://access.redhat.com/errata/RHSA-2025:19403
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:21030 https://access.redhat.com
https://github.com/libexpat/libexpat/blob/676a4c531ec768732fac215da9730b5f50fbd2bf/expat/Changes#L45-L74https://github.com/libexpat/libexpat/blob/R_2_7_2/expat/Changeshttps://github.com/libexpat/libexpat/issues/1018https://github.com/libexpat/libexpat/pull/1034https://issues.oss-fuzz.com/issues/439133977http://www.openwall.com/lists/oss-security/2025/09/16/2http://www.openwall.com/lists/oss-security/2026/05/01/5https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-089022.html
2025-09-15
Published