CVE-2026-25210
published 2026-01-30CVE-2026-25210: In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
9.1th percentile
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | < expat 2.7.4-1 (forky) | expat 2.7.4-1 (forky) |
| libexpat_project | libexpat | < 2.7.4 | 2.7.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2026-02-16·CVSS 2.9
CVE-2026-24515 [LOW] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
USN-8022-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that Expat incorrectly handled the initialization of parsers
for external entities. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-24515)
It was discovered that Expat incorrectly handled integer calculations when
allocating memory for XML tags. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2026-25210)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2026-02-11·CVSS 2.9
CVE-2026-24515 [LOW] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in the xmltok library.
It was discovered that Expat, contained within the xmltok library, incorrectly
handled the initialization of parsers for external entities. An attacker could
possibly use this issue to cause a denial of service. (CVE-2026-24515)
It was discovered that Expat, contained within the xmltok library, incorrectly
handled integer calculations when allocating memory for XML tags. An attacker
could possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2026-25210)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2026-02-10·CVSS 7.5
CVE-2026-24515 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
It was discovered that Expat incorrectly handled memory when parsing certain
XML files. An attacker could possibly use this issue to cause a denial of
service. This issue was only addressed in Ubuntu 25.10. (CVE-2025-59375)
It was discovered that Expat incorrectly handled the initialization of parsers
for external entities. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-24515)
It was discovered that Expat incorrectly handled integer calculations when
allocating memory for XML tags. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2026-25210)
Instructions: In general, a standard system update will make all the necess
Red Hat
libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
vendor_redhat·2026-01-30·CVSS 6.9
CVE-2026-25210 [MEDIUM] CWE-190 libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
A flaw was found in libexpat. A local attacker could exploit an integer overflow vulnerability in the doContent function. This flaw occurs because the buffer size is not properly determined during tag buffer reallocation, which can lead to memory corruption. Successful exploitation may result in information disclosure and data integrity issues.
Package: expat (Red Hat Enterprise Linux 10) - Not affected
Package: compat-expat1 (Red Hat Enterprise Linux 6) - Not affected
Package: expat (Red Hat Enterpri
Debian
CVE-2026-25210: expat - In libexpat before 2.7.4, the doContent function does not properly determine the...
vendor_debian·2026·CVSS 6.9
CVE-2026-25210 [MEDIUM] CVE-2026-25210: expat - In libexpat before 2.7.4, the doContent function does not properly determine the...
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.4-1)
sid: resolved (fixed in 2.7.4-1)
trixie: open
OSV
expat vulnerabilities
osv·2026-02-16·CVSS 2.5
CVE-2026-24515 [LOW] expat vulnerabilities
expat vulnerabilities
USN-8022-1 fixed vulnerabilities in Expat. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that Expat incorrectly handled the initialization of parsers
for external entities. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-24515)
It was discovered that Expat incorrectly handled integer calculations when
allocating memory for XML tags. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2026-25210)
OSV
libxmltok vulnerabilities
osv·2026-02-11·CVSS 2.5
CVE-2026-24515 [LOW] libxmltok vulnerabilities
libxmltok vulnerabilities
It was discovered that Expat, contained within the xmltok library, incorrectly
handled the initialization of parsers for external entities. An attacker could
possibly use this issue to cause a denial of service. (CVE-2026-24515)
It was discovered that Expat, contained within the xmltok library, incorrectly
handled integer calculations when allocating memory for XML tags. An attacker
could possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2026-25210)
OSV
expat vulnerabilities
osv·2026-02-10·CVSS 7.5
CVE-2025-59375 [HIGH] expat vulnerabilities
expat vulnerabilities
It was discovered that Expat incorrectly handled memory when parsing certain
XML files. An attacker could possibly use this issue to cause a denial of
service. This issue was only addressed in Ubuntu 25.10. (CVE-2025-59375)
It was discovered that Expat incorrectly handled the initialization of parsers
for external entities. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-24515)
It was discovered that Expat incorrectly handled integer calculations when
allocating memory for XML tags. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2026-25210)
GHSA
GHSA-857q-6v86-xp84: In libexpat before 2
ghsa_unreviewed·2026-01-30
CVE-2026-25210 [MEDIUM] CWE-190 GHSA-857q-6v86-xp84: In libexpat before 2
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
OSV
CVE-2026-25210: In libexpat before 2
osv·2026-01-30·CVSS 7.8
CVE-2026-25210 [HIGH] CVE-2026-25210: In libexpat before 2
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-25210 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-25210 [MEDIUM] CVE-2026-25210 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25210 :
Alma Linux vulnerability analysis and mitigation
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Source : NVD
## 7.8
Score
Published January 30, 2026
Severity HIGH
CNA Score 6.9
Affected Technologies
Alma Linux
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libxmltok
libexpat1
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23 Severity HIGH Has Fix Added at: Feb 04, 2026
Alpine edge Severity HIGH Has Fix Added at: Feb 03, 2026
CBL-Mariner 2.0 Severity MEDIUM
Bugzilla
CVE-2026-25210 libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
bugzilla·2026-01-30·CVSS 7.8
CVE-2026-25210 [HIGH] CVE-2026-25210 libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
CVE-2026-25210 libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
2026-01-30
Published