← Back

Libexpat Project

libexpat_project

62 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Libexpat
libexpat

CVEs (62)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 21, 2026
N/A· v4
5.9 MEDIUM· v3
N/A· v2
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can oc...Show more
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.Show less
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 21, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 21, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 21, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 21, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
libexpat before 2.8.2 has an integer overflow in copyString.
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 21, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 21, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 21, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
libexpat before 2.8.2 has an integer overflow in getAttributeId.
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 21, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
libexpat before 2.8.2 has an integer overflow in addBinding.
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 21, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
libexpat before 2.8.2 has an integer overflow in storeAtts.
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 19, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
1Libexpat Project
1Libexpat
Jun 23, 2026
Jun 19, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
1Libexpat Project
1Libexpat
Jul 22, 2026
Jun 4, 2026
N/A· v4
5.9 MEDIUM· v3
N/A· v2
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-fr...Show more
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,Show less
2Libexpat Project
Python
2Libexpat
Python
Jun 17, 2026
May 11, 2026
6.3 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requir...Show more
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.Show less
1Libexpat Project
1Libexpat
Jul 24, 2026
May 10, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
1Libexpat Project
1Libexpat
Jul 14, 2026
Apr 16, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
1Libexpat Project
1Libexpat
Jul 14, 2026
Mar 16, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
1Libexpat Project
1Libexpat
Jul 14, 2026
Mar 16, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
1Libexpat Project
1Libexpat
Jul 14, 2026
Mar 16, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
1Libexpat Project
1Libexpat
Jun 17, 2026
Jan 30, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.