VDB

CISA-2026-25210

CISA-2026-25210 PUBLISHED CVSS 6.9 MEDIUM

Reported by mitre · Published January 30, 2026

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

Risk Scores

CVSS 3.1
6.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Affected Products

VendorProductVersions
libexpat projectlibexpat0
libexpat_projectlibexpat0, 0
libexpat projectlibexpat0, 0

Timeline

  • Jan 30, 2026 CVE Published
  • Feb 3, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›