apk package
wolfi/libexpat1
pkg:apk/wolfi/libexpat1
Vulnerabilities (14)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-56412 | Med | 4.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 21, 2026 | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix fo | |
| CVE-2026-56411 | Med | 6.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. | |
| CVE-2026-56410 | Med | 6.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. | |
| CVE-2026-56409 | Med | 6.5 | < 2.8.2-r0 | 2.8.2-r0 | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. | |
| CVE-2026-56408 | Med | 6.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in copyString. | |
| CVE-2026-56406 | Med | 6.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. | |
| CVE-2026-56405 | Med | 6.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in getAttributeId. | |
| CVE-2026-56404 | Med | 6.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in addBinding. | |
| CVE-2026-56403 | Med | 6.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in storeAtts. | |
| CVE-2026-56132 | Med | 6.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 19, 2026 | In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers. | |
| CVE-2026-56131 | Med | 4.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 19, 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). | |
| CVE-2026-50219 | Med | 4.9 | < 2.8.2-r0 | 2.8.2-r0 | Jun 4, 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, | |
| CVE-2022-43680 | Hig | 7.5 | < 0 | 0 | Oct 24, 2022 | In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. | |
| CVE-2022-40674 | Hig | 8.1 | < 0 | 0 | Sep 14, 2022 | libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. |
- affected < 2.8.2-r0fixed 2.8.2-r0
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix fo
- affected < 2.8.2-r0fixed 2.8.2-r0
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
- affected < 2.8.2-r0fixed 2.8.2-r0
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
- affected < 2.8.2-r0fixed 2.8.2-r0
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
- affected < 2.8.2-r0fixed 2.8.2-r0
libexpat before 2.8.2 has an integer overflow in copyString.
- affected < 2.8.2-r0fixed 2.8.2-r0
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
- affected < 2.8.2-r0fixed 2.8.2-r0
libexpat before 2.8.2 has an integer overflow in getAttributeId.
- affected < 2.8.2-r0fixed 2.8.2-r0
libexpat before 2.8.2 has an integer overflow in addBinding.
- affected < 2.8.2-r0fixed 2.8.2-r0
libexpat before 2.8.2 has an integer overflow in storeAtts.
- affected < 2.8.2-r0fixed 2.8.2-r0
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
- affected < 2.8.2-r0fixed 2.8.2-r0
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
- affected < 2.8.2-r0fixed 2.8.2-r0
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
- affected < 0fixed 0
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
- affected < 0fixed 0
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.