The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Sep 20, 2017 | Jun 16, 2016 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Mar 24, 2017 | Jun 16, 2016 |
| Debian | — | Upgrade expat | Jun 7, 2016 | Jun 7, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Oct 26, 2016 |
| Freebsd | — | Upgrade expatUpgrade python27 | Oct 11, 2017 | Jun 9, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Oct 30, 2017 | Jun 16, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade expatUpgrade expat-devel | Jul 23, 2019 | Jun 16, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade expat-develUpgrade expat | Sep 25, 2019 | Jun 16, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade expatUpgrade expat-devel | Jun 27, 2019 | Jun 16, 2016 |
| Oracle Solaris | — | Upgrade library/expat to version 2.2.0-0.175.3.11.0.4.0 on Solaris 11.3 | May 29, 2017 | Jun 16, 2016 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Jun 4, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 4, 2016 |
| Suse | — | Upgrade sles12-docker-imageUpgrade sles12sp1-docker-imageUpgrade sles12sp2-docker-imageUpgrade libexpat1Upgrade libexpat-develUpgrade libexpat1-x86Upgrade expatUpgrade libexpat1-32bit | Feb 3, 2017 | Jun 16, 2016 |
| Ubuntu | — | Upgrade libxmlrpc-core-c3Upgrade libxmlrpc-c++4Upgrade libexpat1Upgrade lib64expat1 | Jun 20, 2016 | Jun 16, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub