Medium severity5.5NVD Advisory· Published Feb 4, 2024· Updated Jun 17, 2026
CVE-2023-52426
CVE-2023-52426
Description
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*range: <=2.5.0
- (no CPE)
- (no CPE)range: <=2.5.0
- osv-coords3 versionspkg:rpm/opensuse/expat&distro=openSUSE%20Tumbleweedpkg:rpm/suse/expat&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/expat&distro=SUSE%20Linux%20Micro%206.1
< 2.6.0-1.1+ 2 more
- (no CPE)range: < 2.6.0-1.1
- (no CPE)range: < 2.7.1-1.1
- (no CPE)range: < 2.7.1-slfo.1.1_1.1
Patches
Vulnerability mechanics
References
7- github.com/libexpat/libexpat/commit/0f075ec8ecb5e43f8fdca5182f8cca4703da0404nvdPatchVendor Advisory
- github.com/libexpat/libexpat/pull/777nvdVendor Advisory
- cwe.mitre.org/data/definitions/776.htmlnvdTechnical Description
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNUBSGZFEZOBHJFTAD42SAN4ATW2VEMV/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/nvd
- security.netapp.com/advisory/ntap-20240307-0005/nvd
News mentions
0No linked articles in our index yet.