https://seclists.org/oss-sec/2025/q3/170: libexpat 2.7.2 fixes CVE-2025-59375 (DoS, CWE-770)
Published Sep 16, 2025
·Updated
Affected Software
1 affected component
Libexpat expat
Frequently Asked Questions
1
What is the severity of CVE-2025-59375?
CVE-2025-59375 is classified as a denial of service (DoS) vulnerability.
2
How do I fix CVE-2025-59375?
To fix CVE-2025-59375, upgrade to libexpat version 2.7.2 or later.
3
What causes CVE-2025-59375?
CVE-2025-59375 is caused by the extensive use of dynamic memory in response to small input in the parser.
4
Which software is affected by CVE-2025-59375?
The vulnerability affects libexpat, specifically versions prior to 2.7.2.
5
When was CVE-2025-59375 published?
CVE-2025-59375 was published on September 16, 2025.