VDB
CISA-2026-25210
CISA-2026-25210
PUBLISHED
CVSS 6.9 MEDIUM
Reported by mitre · Published January 30, 2026
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Risk Scores
CVSS 3.1
6.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| libexpat project | libexpat | 0 |
| libexpat_project | libexpat | 0, 0 |
| libexpat project | libexpat | 0, 0 |
Timeline
- Jan 30, 2026 CVE Published
- Feb 3, 2026 CVE Updated