📦

libexpat

Vendor: libexpat_project

Actively Exploited 0 CISA KEV List
PoC / Exploits 12 Code Available
Total RCEs 2 Remote Access
Total CVEs 145 Total Indexed
Avg. EPSS 4.30% Exploit Prob.
Latest CVE CVE-2026-56412 Jun 21

Security Vulnerability Index

Page 5 / 15
8.8 CVSS

nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

EPSS: 2.80%
8.8 CVSS

lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

EPSS: 2.64%
9.8 CVSS

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

EPSS: 3.40%
9.8 CVSS

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

EPSS: 3.40%
9.8 CVSS
CVE-2022-22822
Exploit Found

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

EPSS: 4.83%
8.1 CVSS
CVE-2021-46143
Exploit Found

In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.

EPSS: 3.79%
8.8 CVSS
CVE-2021-45960
Exploit Found

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

EPSS: 4.23%
7.5 CVSS

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

EPSS: 6.71%
7.5 CVSS

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).

EPSS: 7.11%
7.8 CVSS

The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working directory because of an untrusted search path, aka DLL hijacking.

EPSS: 0.47%