CVE-2026-32777: Medium severity libexpat vulnerability
Last updated 21 September 2026
Other sources
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/expatto a version that resolves this vulnerability.Fixed in 2.8.3-1~deb13u1Fixed in 2.8.4-1Fixed in 2.8.4-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.6.4-5 - Upgrade
Upgrade
libexpatto a version that resolves this vulnerability.Fixed in 2.7.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32777?
CVE-2026-32777 has a high severity due to the potential for an infinite loop when parsing DTD content.
How do I fix CVE-2026-32777?
To fix CVE-2026-32777, update to libexpat version 2.7.5 or later.
What types of applications are affected by CVE-2026-32777?
CVE-2026-32777 affects applications that use libexpat versions below 2.7.5 for XML parsing.
What vulnerabilities does CVE-2026-32777 introduce?
CVE-2026-32777 introduces the risk of application denial of service due to the infinite loop behavior.
Is CVE-2026-32777 related to XML parsing?
Yes, CVE-2026-32777 specifically involves vulnerabilities in the XML parsing process related to DTD content.