The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Sep 20, 2017 | Jun 16, 2016 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Mar 24, 2017 | Jun 16, 2016 |
| Debian | — | Upgrade expat | Jun 7, 2016 | Jun 7, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Oct 26, 2016 |
| Freebsd | — | Upgrade expatUpgrade python27 | Oct 11, 2017 | Jun 9, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Oct 30, 2017 | Jun 16, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade expat-develUpgrade expat | Jul 23, 2019 | Jun 16, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade expat-develUpgrade expat | Sep 25, 2019 | Jun 16, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade expatUpgrade expat-devel | Jun 27, 2019 | Jun 16, 2016 |
| Oracle Solaris | — | Upgrade library/expat to version 2.2.0-0.175.3.11.0.4.0 on Solaris 11.3 | May 29, 2017 | Jun 16, 2016 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Jun 4, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 4, 2016 |
| Suse | — | Upgrade libexpat1-x86Upgrade libexpat1Upgrade expatUpgrade libexpat1-32bitUpgrade libexpat-develUpgrade sles12sp1-docker-imageUpgrade sles12sp2-docker-imageUpgrade sles12-docker-image | Feb 3, 2017 | Jun 16, 2016 |
| Ubuntu | — | Upgrade lib64expat1Upgrade libexpat1Upgrade libxmlrpc-core-c3Upgrade libxmlrpc-c++4 | Jun 20, 2016 | Jun 16, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub