PT-2026-102681 · Libexpat · Libexpat

·

CVE-2026-102633

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102633

Affected Products

Libexpat