CVE-2026-32777
published 2026-03-16CVE-2026-32777: libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.2th percentile
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | < expat 2.7.5-1 (forky) | expat 2.7.5-1 (forky) |
| libexpat_project | libexpat | < 2.7.5 | 2.7.5 |
| msrc | azl3_cmake_3.30.3-12_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.4-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.9-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cmake_3.21.4-21_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.4-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-19_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian4.0MEDIUM
vendor_msrc4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
vendor_redhat·2026-03-16·CVSS 4.0
CVE-2026-32777 [MEDIUM] libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted Document Type Definition (DTD) content. This could lead to an infinite loop during parsing, resulting in a Denial of Service (DoS) for the application using libexpat.
Statement: This MODERATE impact flaw in libexpat can lead to a denial of service when processing specially crafted Document Type Definition (DTD) content, causing an infinite loop during parsing.
Package: expat (Red Hat Enterprise Linux 10) - Fix deferred
Package: compat-expat1 (Red Hat Enterprise Linux 6) - Fix deferred
Package: expat (Red Hat Enterprise Linux
Microsoft
CVE-2026-32777: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
vendor_msrc·2026-03-10·CVSS 4.0
CVE-2026-32777 [MEDIUM] CWE-835 CVE-2026-32777: Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Debian
CVE-2026-32777: expat - libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
vendor_debian·2026·CVSS 4.0
CVE-2026-32777 [MEDIUM] CVE-2026-32777: expat - libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.5-1)
sid: resolved (fixed in 2.7.5-1)
trixie: open
GHSA
GHSA-9rpf-mhcj-gv7r: libexpat before 2
ghsa_unreviewed·2026-03-16
CVE-2026-32777 [MEDIUM] CWE-835 GHSA-9rpf-mhcj-gv7r: libexpat before 2
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
OSV
CVE-2026-32777: libexpat before 2
osv·2026-03-16·CVSS 5.5
CVE-2026-32777 [MEDIUM] CVE-2026-32777: libexpat before 2
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-32777 libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
bugzilla·2026-03-16·CVSS 5.5
CVE-2026-32777 [MEDIUM] CVE-2026-32777 libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
CVE-2026-32777 libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Wiz
CVE-2026-32777 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-32777 [MEDIUM] CVE-2026-32777 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32777 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libexpat1
seal-expat
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 19, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 17, 2026
Echo Severity MEDIUM Has Fix Added at: Mar 17, 2026
Red
2026-03-16
Published