cbcvebase.
CVE-2026-32777
published 2026-03-16

CVE-2026-32777: libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.2th percentile
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianexpat< expat 2.7.5-1 (forky)expat 2.7.5-1 (forky)
libexpat_projectlibexpat< 2.7.52.7.5
msrcazl3_cmake_3.30.3-12_on_azure_linux_3.0
msrcazl3_expat_2.6.4-4_on_azure_linux_3.0
msrcazl3_python3_3.12.9-9_on_azure_linux_3.0
msrccbl2_cmake_3.21.4-21_on_cbl_mariner_2.0
msrccbl2_expat_2.6.4-4_on_cbl_mariner_2.0
msrccbl2_python3_3.9.19-19_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian4.0MEDIUM
vendor_msrc4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.