Libexpat Project
Libexpat Project Libexpat: vulnerabilidades y CVE
Libexpat Project Libexpat tiene 64 vulnerabilidades publicadas, 24 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE64
Últimos 12 meses24
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76957 | Alta (7.8) | 0.11% | — | 20 ago 2026 | libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412. |
| CVE-2026-76956 | Alta (7.5) | 0.29% | — | 20 ago 2026 | In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted… |
| CVE-2026-66046 | Alta (8.7) | 0.74% | — | 18 ago 2026 | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values… |
| CVE-2026-56412 | Media (5.9) | 0.18% | — | 21 jun 2026 | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can… |
| CVE-2026-56411 | Media (6.9) | 0.13% | — | 21 jun 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. |
| CVE-2026-56410 | Media (6.9) | 0.13% | — | 21 jun 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. |
| CVE-2026-56409 | Media (6.5) | 0.12% | — | 21 jun 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. |
| CVE-2026-56408 | Media (6.9) | 0.13% | — | 21 jun 2026 | libexpat before 2.8.2 has an integer overflow in copyString. |
| CVE-2026-56407 | Media (6.9) | 0.17% | — | 21 jun 2026 | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. |
| CVE-2026-56406 | Media (6.9) | 0.17% | — | 21 jun 2026 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. |
| CVE-2026-56405 | Media (6.9) | 0.13% | — | 21 jun 2026 | libexpat before 2.8.2 has an integer overflow in getAttributeId. |
| CVE-2026-56404 | Media (6.9) | 0.13% | — | 21 jun 2026 | libexpat before 2.8.2 has an integer overflow in addBinding. |
| CVE-2026-56403 | Media (6.9) | 0.17% | — | 21 jun 2026 | libexpat before 2.8.2 has an integer overflow in storeAtts. |
| CVE-2026-56132 | Media (6.9) | 0.10% | — | 19 jun 2026 | In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers. |
| CVE-2026-56131 | Media (4.9) | 0.18% | — | 19 jun 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). |
| CVE-2026-50219 | Media (5.9) | 0.18% | — | 4 jun 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a… |
| CVE-2026-45186 | Alta (7.5) | 0.48% | — | 10 may 2026 | In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. |
| CVE-2026-41080 | Baja (2.9) | 0.40% | — | 16 abr 2026 | libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. |
| CVE-2026-32778 | Media (5.5) | 0.16% | — | 16 mar 2026 | libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition. |
| CVE-2026-32777 | Media (5.5) | 0.17% | — | 16 mar 2026 | libexpat before 2.7.5 allows an infinite loop while parsing DTD content. |
| CVE-2026-32776 | Media (5.5) | 0.16% | — | 16 mar 2026 | libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content. |
| CVE-2026-25210 | Alta (7.8) | 0.21% | — | 30 ene 2026 | In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation. |
| CVE-2026-24515 | Baja (2.5) | 0.19% | — | 23 ene 2026 | In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data. |
| CVE-2025-66382 | Media (5.5) | 0.20% | — | 28 nov 2025 | In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time. |
| CVE-2025-59375 | Alta (7.5) | 1.3% | — | 15 sept 2025 | libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. |
| CVE-2024-50602 | Media (5.9) | 1.0% | — | 27 oct 2024 | An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. |
| CVE-2024-45492 | Crítica (9.8) | 1.4% | — | 30 ago 2024 | An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX). |
| CVE-2024-45491 | Crítica (9.8) | 1.1% | — | 30 ago 2024 | An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX). |
| CVE-2024-45490 | Alta (7.5) | 1.7% | — | 30 ago 2024 | An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. |
| CVE-2024-28757 | Alta (7.5) | 2.0% | — | 10 mar 2024 | libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). |