In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVSS Details
- CVSS 3.1 Base Score: 6.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade expat | Jun 29, 2026 | Jun 19, 2026 |
| Amazon Linux Ami 2 | — | Upgrade expat-staticUpgrade expat-debuginfoUpgrade expatUpgrade thunderbirdUpgrade firefoxUpgrade expat-devel | Jul 8, 2026 | Jul 8, 2026 |
| Amazon_linux_2023 | — | Upgrade expat-develUpgrade firefox-debuginfoUpgrade expat-debuginfoUpgrade expat-debugsourceUpgrade firefoxUpgrade expat-staticUpgrade expatUpgrade firefox-debugsource | Jul 8, 2026 | Jun 19, 2026 |
| Debian | — | Upgrade expat | Aug 2, 2026 | Aug 2, 2026 |
| Freebsd | — | Upgrade expatUpgrade linux-c7-expatUpgrade linux-rl9-expat | Jun 30, 2026 | Jun 28, 2026 |
| Ibm Aix | — | Apply the fix or workaround for python_advisory20 | Jul 15, 2026 | Jul 14, 2026 |
| Redhat_linux | — | No solution existsUpgrade expat-develUpgrade expat-debugsourceUpgrade expat-debuginfoUpgrade expat | Jul 17, 2026 | Jun 19, 2026 |
| Rocky_linux | — | Upgrade expat-debuginfoUpgrade expat-develUpgrade expatUpgrade expat-debugsource | Sep 10, 2026 | Sep 9, 2026 |
| Ubuntu | — | Upgrade expatUpgrade expat (Ubuntu Pro) | Sep 24, 2026 | Jun 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub