cbcvebase.

Libexpat Project Libexpat vulnerabilities

61 known vulnerabilities affecting libexpat_project/libexpat.

Total CVEs
61
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH21MEDIUM28LOW2

Vulnerabilities

Page 3 of 4
CVE-2026-56408P4MEDIUMCVSS 6.9fixed in 2.8.22026-06-21
CVE-2026-56408 [MEDIUM] CWE-190 CVE-2026-56408: libexpat before 2.8.2 has an integer overflow in copyString. libexpat before 2.8.2 has an integer overflow in copyString.
nvd
CVE-2026-56403P4MEDIUMCVSS 6.9fixed in 2.8.22026-06-21
CVE-2026-56403 [MEDIUM] CWE-190 CVE-2026-56403: libexpat before 2.8.2 has an integer overflow in storeAtts. libexpat before 2.8.2 has an integer overflow in storeAtts.
nvd
CVE-2026-56405P4MEDIUMCVSS 6.9fixed in 2.8.22026-06-21
CVE-2026-56405 [MEDIUM] CWE-190 CVE-2026-56405: libexpat before 2.8.2 has an integer overflow in getAttributeId. libexpat before 2.8.2 has an integer overflow in getAttributeId.
nvd
CVE-2026-56407P4MEDIUMCVSS 6.9fixed in 2.8.22026-06-21
CVE-2026-56407 [MEDIUM] CWE-190 CVE-2026-56407: libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and en libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
nvd
CVE-2026-56406P4MEDIUMCVSS 6.9fixed in 2.8.22026-06-21
CVE-2026-56406 [MEDIUM] CWE-190 CVE-2026-56406: libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
nvd
CVE-2012-6702P4MEDIUMCVSS 5.9fixed in 2.2.02016-06-16
CVE-2012-6702 [MEDIUM] CWE-310 CVE-2012-6702: Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
nvd
CVE-2026-56409P4MEDIUMCVSS 6.5fixed in 2.8.22026-06-21
CVE-2026-56409 [MEDIUM] CWE-190 CVE-2026-56409: xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
nvd
CVE-2026-50219P4MEDIUMCVSS 5.9fixed in 2.8.22026-06-04
CVE-2026-50219 [MEDIUM] CWE-416 CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_P libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
nvd
CVE-2024-50602P4MEDIUMCVSS 5.9fixed in 2.6.42024-10-27
CVE-2024-50602 [MEDIUM] CWE-754 CVE-2024-50602: An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser funct An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
nvd
CVE-2026-56412P4MEDIUMCVSS 5.9fixed in 2.8.22026-06-21
CVE-2026-56412 [MEDIUM] CVE-2026-56412: libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
nvd
CVE-2023-52426P4MEDIUMCVSS 5.5≤ 2.5.02024-02-04
CVE-2023-52426 [MEDIUM] CWE-776 CVE-2023-52426: libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.
nvd
CVE-2026-32778P4MEDIUMCVSS 5.5fixed in 2.7.52026-03-16
CVE-2026-32778 [MEDIUM] CWE-476 CVE-2026-32778: libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
nvd
CVE-2012-0876P4MEDIUMCVSS 4.3fixed in 2.1.02012-07-03
CVE-2012-0876 [MEDIUM] CWE-400 CVE-2012-0876: The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the abili The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
nvd
CVE-2012-1148P4MEDIUMCVSS 5.0≤ 2.0.1v1.95.1+7 more2012-07-03
CVE-2012-1148 [MEDIUM] CWE-399 CVE-2012-1148: Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-de Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
nvd
CVE-2026-32777P4MEDIUMCVSS 5.5fixed in 2.7.52026-03-16
CVE-2026-32777 [MEDIUM] CWE-835 CVE-2026-32777: libexpat before 2.7.5 allows an infinite loop while parsing DTD content. libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
nvd
CVE-2025-66382P4MEDIUMCVSS 5.5≤ 2.7.32025-11-28
CVE-2025-66382 [MEDIUM] CWE-407 CVE-2025-66382: In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of se In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
nvd
CVE-2026-32776P4MEDIUMCVSS 5.5fixed in 2.7.52026-03-16
CVE-2026-32776 [MEDIUM] CWE-476 CVE-2026-32776: libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
nvd
CVE-2026-56131P4MEDIUMCVSS 4.9fixed in 2.8.22026-06-19
CVE-2026-56131 [MEDIUM] CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within ha libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
nvd
CVE-2012-1147P4MEDIUMCVSS 4.3≤ 2.0.1v1.95.1+7 more2012-07-03
CVE-2012-1147 [MEDIUM] CWE-20 CVE-2012-1147: readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.
nvd
CVE-2026-41080P4LOWCVSS 2.9fixed in 2.8.02026-04-16
CVE-2026-41080 [LOW] CWE-331 CVE-2026-41080: libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
nvd
Libexpat Project Libexpat vulnerabilities | cvebase