VYPR

by Libexpat

Source repositories

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-45186Low0.122.90.00May 10, 2026In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
CVE-2026-252100.000.00Jan 30, 2026In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
CVE-2026-245150.000.00Jan 23, 2026In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.