Libexpat
68 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Libexpat, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Libexpat CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 2 |
| 2026-02 | 0 |
| 2026-03 | 3 |
| 2026-04 | 1 |
| 2026-05 | 1 |
| 2026-06 | 13 |
| 2026-07 | 0 |
| 2026-08 | 5 |
| 2026-09 | 1 |
Severity
How the 68 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical10
- High23
- Medium30
- Low5
Latest CVEs
The 15 most recently published vulnerabilities affecting Libexpat.
- CVE-2026-93990Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate7.5
- CVE-2026-76641Expat Out-of-Bounds Read via dtdCopy7.5
- CVE-2026-76957libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.4.9
- CVE-2026-76956In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial o...5.9
- CVE-2026-66046Expat Denial of Service via storeAtts() Quadratic Complexity7.5
- CVE-2026-72522libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.6.2
- CVE-2026-56412libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, ...4.9
- CVE-2026-56411xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.6.9
- CVE-2026-56410xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.6.9
- CVE-2026-56409xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.6.5
- CVE-2026-56408libexpat before 2.8.2 has an integer overflow in copyString.6.9
- CVE-2026-56407libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.6.9
- CVE-2026-56406libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.6.9
- CVE-2026-56405libexpat before 2.8.2 has an integer overflow in getAttributeId.6.9
- CVE-2026-56404libexpat before 2.8.2 has an integer overflow in addBinding.6.9
Product grouping is registry-driven, with AI assist and human review. How it works