cbcvebase.
CVE-2025-59375
published 2025-09-15

CVE-2025-59375: libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_18.7.5_and_ipados
appleios_26.3_and_ipados
applemacos_sequoia
applemacos_sonoma
applemacos_tahoe
appletvos
applevisionos
applewatchos
debianexpat< expat 2.7.2-1 (forky)expat 2.7.2-1 (forky)
debianfirefox< expat 2.7.2-1 (forky)expat 2.7.2-1 (forky)
debianfirefox-esr< expat 2.7.2-1 (forky)expat 2.7.2-1 (forky)
debianthunderbird< expat 2.7.2-1 (forky)expat 2.7.2-1 (forky)
libexpat_projectlibexpat< 2.7.22.7.2
mozillafirefox
mozillathunderbird>= 0 < 1:140.9.0esr-1~deb11u11:140.9.0esr-1~deb11u1
mozillathunderbird>= 0 < 1:140.9.0esr-1~deb12u11:140.9.0esr-1~deb12u1
mozillathunderbird>= 0 < 1:140.9.0esr-1~deb13u11:140.9.0esr-1~deb13u1
mozillathunderbird>= 0 < 1:140.9.0esr-11:140.9.0esr-1
msrcazl3_cmake_3.30.3-9_on_azure_linux_3.0
msrcazl3_expat_2.6.4-1_on_azure_linux_3.0
msrcazl3_expat_2.6.4-2_on_azure_linux_3.0
msrcazl3_python3_3.12.9-4_on_azure_linux_3.0
msrccbl2_cmake_3.21.4-18_on_cbl_mariner_2.0
msrccbl2_expat_2.6.4-1_on_cbl_mariner_2.0
msrccbl2_expat_2.6.4-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH