See how expat compares to other vendors in security performance
Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XMLUNICODE and to silently replace input characters in other builds.
Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XMLExternalEntityParserCreate. A struct size mismatch between ELEMENTTYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046.
xml.parsers.expat and xml.etree.ElementTree use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
Hello oss-security,
just a quick note that libexpat 2.8.5 (or "Expat 2.8.5") released today is fixing CVE-2026-93990:
Reject high surrogates not followed by a low surrogate during UTF-16 decoding; previously, malformed UTF-16 could be smuggled into the application using Expat and could cause arbitrary damage there, depending on how malformed UTF-16 was handled inside the application; validation was not their job but Expat's. This is similar to past vulnerability CVE-2022-25235. Upstream CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVSS score: 9.8)
Some key links are:
- The blog post about it https://blog.hartwork.org/posts/expat-2-8-5-released/
- The change log of release 2.8.5 https://github.com/libexpat/libexpat/blob/R285/expat/Changes
- The fixing pull request https://github.com/libexpat/libexpat/pull/1282
- The NVD CVE metadata https://nvd.nist.gov/vuln/detail/CVE-2026-93990 (with a different CVSS vector)
Best
Sebastian
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
Accessibility. A privacy issue was addressed by removing sensitive data.
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINTMAX equals SIZEMAX).
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XMLParseBuffer.
The libexpat library is vulnerable to a stack overflow due to uncontrolled recursion when processing deeply nested XML entities. This can cause the application to crash, resulting in a denial of service (DoS) or potentially leading to memory corruption, depending on the user's environment and how the library is used. The issue is triggered by supplying a specially crafted XML document designed to create a long chain of recursive entities.
Last updated 21 September 2026
Last updated 21 September 2026
Last updated 21 September 2026
Last updated 21 September 2026
Last updated 24 September 2026
Last updated 21 September 2026
Last updated 24 September 2026
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
Last updated 21 September 2026
libexpat before 2.8.2 lacks handler call depth tracking for calls to XMLResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.
Last updated 24 September 2026
Last updated 24 September 2026
Last updated 24 September 2026
Last updated 21 September 2026
The Expat XML parser mishandles certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. The overflows can manifest as a segmentation fault or as memory corruption during a parse operation. The bugs allow for a denial of service attack in many applications by an unauthenticated attacker, and could conceivably result in remote code execution.
Hello oss-security,
just a quick note that libexpat 2.8.1 (or "Expat 2.8.1") released yesterday is fixing CVE-2026-45186:
Fix quadratic runtime from attribute name collision checks that allowed denial of service attacks through moderately sized crafted XML input (CWE-407). Please note that a layer of compression around XML can significantly reduce the minimum attack payload size.
Some key links are:
- The blog post about it https://blog.hartwork.org/posts/expat-2-8-1-released/
- The change log of release 2.8.1 https://github.com/libexpat/libexpat/blob/R281/expat/Changes
- The fixing pull request https://github.com/libexpat/libexpat/pull/1216
- The NVD CVE metadata https://nvd.nist.gov/vuln/detail/CVE-2026-45186
PS: The CVE database lists an unrealistically low CVSS score for this. The complexity of an attack is very low (not "High") and the attack vector is remote (not "Local"). I have asked Mitre to fix this earlier today. My blog post linked above has a few more words on that topic.
Best
Sebastian
Hello oss-security,
just a quick note that libexpat 2.8.0 (or "Expat 2.8.0") released two days ago is fixing CVE-2026-41080.
Some key links are:
- The blog post about it https://blog.hartwork.org/posts/expat-2-8-0-released/
- The change log of release 2.8.0 https://github.com/libexpat/libexpat/blob/R280/expat/Changes
- The fixing pull request https://github.com/libexpat/libexpat/pull/1183
- The official CVE metadata https://nvd.nist.gov/vuln/detail/CVE-2026-41080
Best
Sebastian