📦

libexpat

Vendor: libexpat_project

Actively Exploited 0 CISA KEV List
PoC / Exploits 12 Code Available
Total RCEs 2 Remote Access
Total CVEs 145 Total Indexed
Avg. EPSS 4.30% Exploit Prob.
Latest CVE CVE-2026-56412 Jun 21

Security Vulnerability Index

Page 1 / 15
4.9 CVSS

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.

EPSS: 0.10%
6.9 CVSS

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

EPSS: 0.11%
6.9 CVSS

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

EPSS: 0.11%
6.5 CVSS

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

EPSS: 0.10%
6.9 CVSS

libexpat before 2.8.2 has an integer overflow in copyString.

EPSS: 0.10%
6.9 CVSS

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

EPSS: 0.10%
6.9 CVSS

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

EPSS: 0.10%
6.9 CVSS

libexpat before 2.8.2 has an integer overflow in getAttributeId.

EPSS: 0.10%
6.9 CVSS

libexpat before 2.8.2 has an integer overflow in addBinding.

EPSS: 0.10%
6.9 CVSS

libexpat before 2.8.2 has an integer overflow in storeAtts.

EPSS: 0.10%