Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Libexpat Project

20 known vulnerabilities

16
MEDIUM
4
LOW

Top Products

libexpat 20
20 CVEs
4.9
CVE-2026-56412

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking

6.9
CVE-2026-56411

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

6.9
CVE-2026-56410

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

6.5
CVE-2026-56409

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

6.9
CVE-2026-56408

libexpat before 2.8.2 has an integer overflow in copyString.

6.9
CVE-2026-56407

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

6.9
CVE-2026-56406

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse

6.9
CVE-2026-56405

libexpat before 2.8.2 has an integer overflow in getAttributeId.

6.9
CVE-2026-56404

libexpat before 2.8.2 has an integer overflow in addBinding.

6.9
CVE-2026-56403

libexpat before 2.8.2 has an integer overflow in storeAtts.

6.9
CVE-2026-56132

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array

4.9
CVE-2026-56131

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a

4.9
CVE-2026-50219

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars

2.9
CVE-2026-45186

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via

2.9
CVE-2026-41080

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

2.9
CVE-2026-32778

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memo

4.0
CVE-2026-32777

libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

4.0
CVE-2026-32776

libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

6.9
CVE-2026-25210

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no

2.9
CVE-2026-24515

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

Frequently Asked Questions

How many CVEs affect Libexpat Project?

Libexpat Project has 20 CVE records in our database, including 0 critical and 0 high severity vulnerabilities.

What are the most severe Libexpat Project vulnerabilities?

Libexpat Project has 0 critical severity (CVSS 9.0+) and 0 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Libexpat Project vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Libexpat Project products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Libexpat Project Vulnerabilities

CyberStrike scans your infrastructure for Libexpat Project vulnerabilities and provides real-time remediation guidance.

Get Started