CVE-2026-102633: libexpat 2.7.2 through 2.8.5 Integer Overflow in expat_realloc
libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expatrealloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.
Affected Software
Event History
Frequently Asked Questions
Which systems are affected?
The issue affects applications that parse attacker-supplied XML using libexpat versions 2.7.2 through 2.8.5 on 32-bit platforms. The provided information does not indicate an impact on 64-bit platforms.
What does an attacker need to exploit this issue?
An attacker needs to supply malicious XML to an application that parses it with a vulnerable libexpat version. No authentication or user interaction is required, but the attack complexity is rated high.
What is the potential impact?
Successful exploitation can cause a heap buffer overflow and memory corruption, or result in denial of service. The supplied severity vector indicates availability impact, with no stated confidentiality or integrity impact.