GHSA-533f-rf84-jgccHighCVSS 5.9

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc(...

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.

🔗 References (7)