Libexpat
This hub aggregates every CVE we track for Libexpat, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
67
CVEs tracked
10
Critical
22
High
0
In CISA KEV
Severity distribution
MEDIUM30HIGH22CRITICAL10LOW5
Monthly trend
1
0
0
0
0
1
0
0
0
0
0
1
0
1
0
2
0
3
1
1
13
0
5
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Libexpat.
- CVE-2026-76641Expat Out-of-Bounds Read via dtdCopy7.5
- CVE-2026-76957libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.4.9
- CVE-2026-76956In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial o...5.9
- CVE-2026-66046Expat Denial of Service via storeAtts() Quadratic Complexity7.5
- CVE-2026-72522libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.6.2
- CVE-2026-56412libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, ...4.9
- CVE-2026-56411xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.6.9
- CVE-2026-56410xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.6.9
- CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.6.5
- CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.6.9
- CVE-2026-56407libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.6.9
- CVE-2026-56406libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.6.9
- CVE-2026-56405libexpat before 2.8.2 has an integer overflow in getAttributeId.6.9
- CVE-2026-56404libexpat before 2.8.2 has an integer overflow in addBinding.6.9
- CVE-2026-56403libexpat before 2.8.2 has an integer overflow in storeAtts.6.9
Product normalization is registry-driven with AI assist and human review. How it works