CVE-2026-102633
libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.
- Published Sep 29, 2026
- CVSS 8.2 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available