📦

libexpat

Vendor: libexpat_project

Actively Exploited 0 CISA KEV List
PoC / Exploits 12 Code Available
Total RCEs 2 Remote Access
Total CVEs 145 Total Indexed
Avg. EPSS 4.30% Exploit Prob.
Latest CVE CVE-2026-56412 Jun 21

Security Vulnerability Index

Page 2 / 15
6.9 CVSS

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

EPSS: 0.11%
4.9 CVSS

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).

EPSS: 0.14%
4.9 CVSS

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,

EPSS: 0.22%
6.3 CVSS

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

EPSS: 0.79%
2.9 CVSS

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

EPSS: 0.43%
2.9 CVSS

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

EPSS: 0.40%
2.9 CVSS

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

EPSS: 0.17%
4.0 CVSS

libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

EPSS: 0.22%
4.0 CVSS

libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

EPSS: 0.16%
6.9 CVSS

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

EPSS: 0.19%