ZeroHour

CVE-2026-25210

CVSS 3.1
7.8 high
EPSS
<1%p9
Published
()
Modified
Description

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

Vendors
libexpat project
Products
libexpat
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.