CVE-2026-25210
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Affected (1)
Products: Libexpat Project: Libexpat
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.4 |
References (3)
Source: cve@mitre.org
Patch
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Timeline
No history available yet.