expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Libexpat | — | Apply Apple macOS Security Update 2021-005 CatalinaUpgrade macOS to the latest version | Nov 17, 2021 | Jan 21, 2014 |
| Debian | — | Upgrade expat | Jul 30, 2024 | Jan 21, 2014 |
| Freebsd | — | Upgrade expat | Dec 10, 2025 | May 24, 2021 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Oct 30, 2017 | Jan 21, 2014 |
| Huawei Euleros 2_0_sp9 | — | Upgrade expat | Sep 29, 2021 | Jan 21, 2014 |
| Ibm Http_server | — | Apply IBM HTTP Server Interim Fix PH50316Apply IBM HTTP Server version 8.5.5.23 or laterApply IBM HTTP Server version 9.0.5.15 or laterApply IBM HTTP Server version 8.0.0.16 or laterApply IBM HTTP Server version 7.0.0.46 or later | Nov 20, 2025 | Nov 22, 2022 |
| Redhat_linux | — | No solution existsUpgrade expatUpgrade expat-debugsourceUpgrade expat-debuginfoUpgrade expat-devel | Jul 9, 2025 | Feb 19, 2013 |
| Suse | — | Upgrade expatUpgrade libexpat1Upgrade libexpat1-32bitUpgrade libexpat-devel | Aug 9, 2024 | Jan 21, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub