libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Mar 20, 2026 | Mar 16, 2026 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade firefox | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade firefoxUpgrade firefox-debuginfoUpgrade firefox-debugsource | Apr 7, 2026 | Mar 16, 2026 |
| Debian | — | Upgrade expat | Aug 2, 2026 | Aug 2, 2026 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Jul 15, 2026 | Jul 14, 2026 |
| Ibm Aix | — | Apply the fix or workaround for python_advisory19 | Apr 16, 2026 | Apr 15, 2026 |
| Ibm Http_server | — | Apply IBM HTTP Server Interim Fix PH70572Apply IBM HTTP Server version 8.5.5.30 or laterApply IBM HTTP Server version 9.0.5.28 or later | Apr 8, 2026 | Apr 1, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 16, 2026 |
| Ubuntu | — | Upgrade libexpat1 (Ubuntu Pro)Upgrade libexpat1Upgrade lib64expat1-dev (Ubuntu Pro)Upgrade expatUpgrade lib64expat1 (Ubuntu Pro)Upgrade expat (Ubuntu Pro)Upgrade libexpat1-devUpgrade libexpat1-dev (Ubuntu Pro) | Sep 22, 2026 | Sep 21, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Mar 16, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub