CVE-2026-32777: Medium severity libexpat vulnerability
Published Mar 16, 2026
·Updated
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Affected Software
5 affected componentsFixes available
libexpat<2.7.5
Libexpat Project Libexpat<2.7.5
Microsoft azl3 expat 2.6.4-4
Microsoft azl3 expat 2.6.4-5
Microsoft cbl2 expat 2.6.4-4
Remediation
Patch Available
Patch Available
Event History
Mar 16, 2026
CVE Published
via MITRE·06:58 AM
Data Sourced
via MITRE·06:58 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:19 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 17, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
Severity
Updated
via Microsoft·08:01 AM
Affected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-32777?
CVE-2026-32777 has a high severity due to the potential for an infinite loop when parsing DTD content.
2
How do I fix CVE-2026-32777?
To fix CVE-2026-32777, update to libexpat version 2.7.5 or later.
3
What types of applications are affected by CVE-2026-32777?
CVE-2026-32777 affects applications that use libexpat versions below 2.7.5 for XML parsing.
4
What vulnerabilities does CVE-2026-32777 introduce?
CVE-2026-32777 introduces the risk of application denial of service due to the infinite loop behavior.
5
Is CVE-2026-32777 related to XML parsing?
Yes, CVE-2026-32777 specifically involves vulnerabilities in the XML parsing process related to DTD content.