VulnSea

libexpat vulnerabilities

CVEs whose affected-version data names the libexpat package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-93990High· 7.5
3d ago

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following c…

Twilightlibexpat · libexpatEPSS 0.35%via NVD
CVE-2026-76957Medium· 4.9
1mo ago

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

Sunlitlibexpat_project · libexpatEPSS 0.11%via NVD
CVE-2026-76956Medium· 5.9
1mo ago

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

Sunlitlibexpat_project · libexpatEPSS 0.29%via NVD
CVE-2026-66046High· 7.5
1mo ago

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) li…

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) li…

Twilightlibexpat_project · libexpatEPSS 0.61%via NVD
CVE-2026-45186Low· 2.9⚖ disputed
4mo ago

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

Sunlitlibexpat_project · libexpatEPSS 0.46%via NVD
CVE-2024-8176High· 7.5PoC
1y ago

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse ind…

MidnightRed Hat · libexpatEPSS 1.3%via NVD
libexpat vulnerabilities (CVEs) · VulnSea