CVE-2025-66382: expat looking for help with another unfixed non-public denial-of-service vulnerability [CVE-2025-66382]
In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.8.2-1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66382?
CVE-2025-66382 has a high severity as it can cause significant processing delays when handling specially crafted files.
How do I fix CVE-2025-66382?
To fix CVE-2025-66382, update libexpat to version 2.7.4 or later, which includes the necessary patches.
What impact does CVE-2025-66382 have on applications using libexpat?
CVE-2025-66382 can lead to performance degradation due to prolonged processing times when parsing large XML files.
Is CVE-2025-66382 a remote vulnerability?
CVE-2025-66382 is not remote; it requires an attacker to supply a specially crafted file to the vulnerable application.
Which versions of libexpat are affected by CVE-2025-66382?
CVE-2025-66382 affects all versions of libexpat up to and including 2.7.3.