The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Aug 30, 2017 | Jul 3, 2012 |
| Apple Osx Libexpat | — | Upgrade macOS to the latest version | Mar 29, 2016 | Jul 3, 2012 |
| Apple Osx Python | — | Upgrade macOS to the latest version | Apr 5, 2017 | Jul 3, 2012 |
| Centos_linux | — | Upgrade expatUpgrade expat-devel | Dec 1, 2016 | Jul 3, 2012 |
| Debian | — | Upgrade xmlrpc-cUpgrade expat | Jul 30, 2024 | Jul 3, 2012 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 11, 2015 |
| Freebsd | — | Upgrade python27 | Oct 11, 2017 | Oct 11, 2017 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Oct 30, 2017 | Jul 3, 2012 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.5.5.11 or laterApply IBM HTTP Server version 8.0.0.13 or laterApply IBM HTTP Server Interim Fix PI73984Apply IBM HTTP Server version 7.0.0.43 or laterApply IBM HTTP Server version 9.0.0.2 or later | Sep 7, 2022 | Sep 7, 2022 |
| Oracle Solaris | — | Upgrade library/expat to version 2.2.0-0.175.3.11.0.4.0 on Solaris 11.3Upgrade library/expat to version 2.0.1-0.175.0.11.0.4.0 on Solaris 11.0Upgrade library/expat to version 2.1.0-0.175.1.0.0.24.0 on Solaris 11.1 | May 29, 2017 | Jul 3, 2012 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Mar 3, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 3, 2012 |
| Suse | — | Upgrade libexpat-develUpgrade libpython3_4m1_0Upgrade python3-baseUpgrade expatUpgrade python3-develUpgrade libexpat1-x86Upgrade python3-tkUpgrade python3Upgrade python3-dbmUpgrade libexpat1-32bitUpgrade libexpat1Upgrade python3-cursesUpgrade libpython3_4m1_0-32bit | Dec 12, 2013 | Jun 27, 2013 |
| Ubuntu | — | Upgrade python2.4Upgrade python2.5-minimalUpgrade python2.4-minimalUpgrade libxmlrpc-core-c3-0Upgrade libexpat1Upgrade lib64expat1Upgrade libexpat1-udebUpgrade libxmlrpc-core-c3Upgrade python2.5 | Nov 8, 2024 | Jul 3, 2012 |
| Vmsa 2012 0016 | — | Upgrade VMware ESX 4.1 to build number 874690 | Nov 22, 2012 | Jul 3, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub