rpm package
opensuse/expat&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/expat&distro=openSUSE%20Tumbleweed
Vulnerabilities (67)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-76641 | Hig | 7.5 | < 2.8.4-1.1 | 2.8.4-1.1 | Aug 20, 2026 | Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to r | |
| CVE-2026-76957 | Med | 4.9 | < 2.8.4-1.1 | 2.8.4-1.1 | Aug 20, 2026 | libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412. | |
| CVE-2026-76956 | Med | 5.9 | < 2.8.4-1.1 | 2.8.4-1.1 | Aug 20, 2026 | In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content. | |
| CVE-2026-66046 | Hig | 7.5 | < 2.8.4-1.1 | 2.8.4-1.1 | Aug 18, 2026 | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to de | |
| CVE-2026-72522 | Med | 6.2 | < 2.8.4-1.1 | 2.8.4-1.1 | Aug 10, 2026 | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions. | |
| CVE-2026-56412 | Med | 4.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 21, 2026 | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix fo | |
| CVE-2026-56411 | Med | 6.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. | |
| CVE-2026-56410 | Med | 6.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. | |
| CVE-2026-56409 | Med | 6.5 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. | |
| CVE-2026-56408 | Med | 6.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in copyString. | |
| CVE-2026-56407 | Med | 6.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. | |
| CVE-2026-56406 | Med | 6.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. | |
| CVE-2026-56405 | Med | 6.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in getAttributeId. | |
| CVE-2026-56404 | Med | 6.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in addBinding. | |
| CVE-2026-56403 | Med | 6.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in storeAtts. | |
| CVE-2026-56132 | Med | 6.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 19, 2026 | In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers. | |
| CVE-2026-56131 | Med | 4.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 19, 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). | |
| CVE-2026-50219 | Med | 4.9 | < 2.8.2-1.1 | 2.8.2-1.1 | Jun 4, 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, | |
| CVE-2026-45186 | Low | 2.9 | < 2.8.1-1.1 | 2.8.1-1.1 | May 10, 2026 | In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. | |
| CVE-2026-41080 | Low | 2.9 | < 2.8.1-1.1 | 2.8.1-1.1 | Apr 16, 2026 | libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. |
- affected < 2.8.4-1.1fixed 2.8.4-1.1
Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to r
- affected < 2.8.4-1.1fixed 2.8.4-1.1
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
- affected < 2.8.4-1.1fixed 2.8.4-1.1
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
- affected < 2.8.4-1.1fixed 2.8.4-1.1
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to de
- affected < 2.8.4-1.1fixed 2.8.4-1.1
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix fo
- affected < 2.8.2-1.1fixed 2.8.2-1.1
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
libexpat before 2.8.2 has an integer overflow in copyString.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
libexpat before 2.8.2 has an integer overflow in getAttributeId.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
libexpat before 2.8.2 has an integer overflow in addBinding.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
libexpat before 2.8.2 has an integer overflow in storeAtts.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
- affected < 2.8.2-1.1fixed 2.8.2-1.1
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
- affected < 2.8.2-1.1fixed 2.8.2-1.1
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
- affected < 2.8.1-1.1fixed 2.8.1-1.1
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
- affected < 2.8.1-1.1fixed 2.8.1-1.1
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Page 1 of 4