CVE-2026-24515: libexpat 2.7.4 fixes CVE-2026-24515 and CVE-2026-25210
In libexpat before 2.7.4, XMLExternalEntityParserCreate does not copy unknown encoding handler user data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libexpatto a version that resolves this vulnerability.Fixed in 2.7.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-24515 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-25210
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24515?
The severity of CVE-2026-24515 is considered moderate due to the potential for unexpected behavior during XML parsing.
How do I fix CVE-2026-24515?
To fix CVE-2026-24515, upgrade to libexpat version 2.7.4 or later where the vulnerability has been addressed.
What software is affected by CVE-2026-24515?
CVE-2026-24515 affects all versions of libexpat prior to 2.7.4.
What are the potential risks of CVE-2026-24515?
The risks of CVE-2026-24515 include the possibility of creating security vulnerabilities if unknown encoding handlers are mismanaged.
Does CVE-2026-24515 affect XML parsing security?
Yes, CVE-2026-24515 can affect XML parsing security due to improper handling of external entities in the parser.