libexpat project libexpat
7 known vulnerabilities in libexpat project libexpat, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-56412 CVSS 5.9 medium libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls…
- CVE-2026-56408 CVSS 6.9 medium libexpat before 2.8.2 has an integer overflow in copyString.
- CVE-2026-56405 CVSS 6.9 medium libexpat before 2.8.2 has an integer overflow in getAttributeId.
- CVE-2026-56404 CVSS 6.9 medium libexpat before 2.8.2 has an integer overflow in addBinding.
- CVE-2026-56403 CVSS 6.9 medium libexpat before 2.8.2 has an integer overflow in storeAtts.
- CVE-2026-56132 CVSS 6.9 medium In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is…
- CVE-2026-50219 CVSS 5.9 medium libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or…