In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
CVSS Details
- CVSS 3.1 Base Score: 2.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Feb 4, 2026 | Jan 23, 2026 |
| Debian | — | Upgrade expat | Aug 2, 2026 | Aug 2, 2026 |
| Freebsd | — | Upgrade expat | Feb 13, 2026 | Feb 10, 2026 |
| Ibm Aix | — | Apply the fix or workaround for perl_advisory13Apply the fix or workaround for python_advisory18 | Mar 18, 2026 | Mar 17, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 23, 2026 |
| Ubuntu | — | Upgrade expat (Ubuntu Pro)Upgrade libexpat1 (Ubuntu Pro)Upgrade lib64expat1 (Ubuntu Pro)Upgrade expatUpgrade libxmltok1t64 (Ubuntu Pro)Upgrade libexpat1Upgrade libxmltok1 (Ubuntu Pro) | Feb 12, 2026 | Jan 23, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub