CVE Tools

Libexpat

68 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Libexpat, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Libexpat CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Libexpat CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-031
2025-040
2025-050
2025-060
2025-070
2025-080
2025-091
2025-100
2025-111
2025-120
2026-012
2026-020
2026-033
2026-041
2026-051
2026-0613
2026-070
2026-085
2026-091

Severity

How the 68 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1015%
  • High2334%
  • Medium3044%
  • Low57%

Latest CVEs

The 15 most recently published vulnerabilities affecting Libexpat.

  1. CVE-2026-93990Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate7.5
  2. CVE-2026-76641Expat Out-of-Bounds Read via dtdCopy7.5
  3. CVE-2026-76957libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.4.9
  4. CVE-2026-76956In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial o...5.9
  5. CVE-2026-66046Expat Denial of Service via storeAtts() Quadratic Complexity7.5
  6. CVE-2026-72522libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.6.2
  7. CVE-2026-56412libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, ...4.9
  8. CVE-2026-56411xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.6.9
  9. CVE-2026-56410xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.6.9
  10. CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.6.5
  11. CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.6.9
  12. CVE-2026-56407libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.6.9
  13. CVE-2026-56406libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.6.9
  14. CVE-2026-56405libexpat before 2.8.2 has an integer overflow in getAttributeId.6.9
  15. CVE-2026-56404libexpat before 2.8.2 has an integer overflow in addBinding.6.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store