📦

libexpat

Vendor: libexpat_project

Actively Exploited 0 CISA KEV List
PoC / Exploits 12 Code Available
Total RCEs 2 Remote Access
Total CVEs 145 Total Indexed
Avg. EPSS 4.30% Exploit Prob.
Latest CVE CVE-2026-56412 Jun 21

Security Vulnerability Index

Page 3 / 15
2.9 CVSS

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

EPSS: 0.17%
2.9 CVSS

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

EPSS: 0.19%
7.5 CVSS

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

EPSS: 1.28%
5.9 CVSS

An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.

EPSS: 1.04%
9.8 CVSS

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

EPSS: 1.39%
9.8 CVSS

An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

EPSS: 1.13%
7.5 CVSS

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

EPSS: 1.69%
7.5 CVSS
CVE-2024-28757
RCE Exploit Found

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

EPSS: 2.01%
5.5 CVSS

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.

EPSS: 0.37%
7.5 CVSS

libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.

EPSS: 1.81%