libexpat 2.9.0 fixes two vulnerabilities
libexpat 2.9.0 patches CVE-2026-77214 and CVE-2026-102633, including a 32-bit integer overflow.
Sebastian Pipping told oss-security that libexpat 2.9.0, also called Expat 2.9.0, fixes two vulnerabilities. CVE-2026-102633 is an integer overflow in expat_realloc on 32-bit platforms. CVE-2026-77214 adds validation of the len parameter against available buffer capacity in XML_ParseBuffer. The note does not say either flaw is being exploited.