Libexpat Project Libexpat vulnerabilities
64 known vulnerabilities affecting libexpat_project/libexpat.
Total CVEs
64
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH23MEDIUM29LOW2
Vulnerabilities
Page 4 of 4
CVE-2026-56131P4MEDIUMCVSS 4.9fixed in 2.8.22026-06-19
CVE-2026-56131 [MEDIUM] CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within ha
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
nvd
CVE-2012-1147P4MEDIUMCVSS 4.3≤ 2.0.1v1.95.1+7 more2012-07-03
CVE-2012-1147 [MEDIUM] CWE-20 CVE-2012-1147: readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service
readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.
nvd
CVE-2026-41080P4LOWCVSS 2.9fixed in 2.8.02026-04-16
CVE-2026-41080 [LOW] CWE-331 CVE-2026-41080: libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
nvd
CVE-2026-24515P4LOWCVSS 2.5fixed in 2.7.42026-01-23
CVE-2026-24515 [LOW] CWE-476 CVE-2026-24515: In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user
In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
nvd
← Previous4 / 4