https://seclists.org/oss-sec/2025/q4/224: expat looking for help with another unfixed non-public denial-of-service vulnerability [CVE-2025-66382]
Published Dec 2, 2025
·Updated
Affected Software
1 affected component
Expat Expat
Frequently Asked Questions
1
What is the severity of CVE-2025-66382?
CVE-2025-66382 has been classified as a denial-of-service vulnerability.
2
How does CVE-2025-66382 affect Expat?
CVE-2025-66382 allows an attacker to cause a denial of service by feeding a specially crafted file to the Expat parser.
3
How do I fix CVE-2025-66382?
Currently, there is no official patch available for CVE-2025-66382 in Expat.
4
When was CVE-2025-66382 reported?
CVE-2025-66382 was reported on September 25, 2025.
5
What is the potential impact of CVE-2025-66382?
The potential impact of CVE-2025-66382 is that it can lead to service interruption due to denial of service.