Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

libexpat — Vulnerabilities & Security Advisories 28

All 28 CVE vulnerabilities found in libexpat, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the libexpat XML parser product, categorized under general software weaknesses and tagged for technical security analysis. It collects a comprehensive list of Common Vulnerabilities and Exposures associated with libexpat, covering reported security issues from its inception through recent years to ensure historical completeness and current relevance for developers and security professionals. Users can utilize this resource to track vendor advisories from the original maintainers, understand the specific characteristics of identified weakness classes such as buffer overflows or injection flaws, and look up the product's complete vulnerability history to assess long-term stability and remediation efforts. By centralizing this information, the page aids in risk assessment, patch management, and compliance verification without requiring users to search multiple disparate sources. The data is organized to facilitate quick identification of critical issues that may impact systems relying on the libexpat library for XML processing. This approach supports informed decision-making for system administrators and software engineers who need to evaluate the security posture of their dependencies. The content is strictly factual, focusing on technical details and timelines to support accurate security auditing and maintenance workflows. All entries are derived from official advisories and recognized vulnerability databases to ensure reliability and authority. This consolidated view helps streamline the process of addressing security gaps in projects that depend on libexpat.

Vendor: libexpat project

CVE ID Title CVSS Severity Published
CVE-2026-93990 Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate CWE-176 7.5 High 2026-09-19
CVE-2026-76641 Expat Out-of-Bounds Read via dtdCopy CWE-125 7.5 High 2026-08-20
CVE-2026-76957 libexpat 资源管理错误漏洞 CWE-416 4.9 Medium 2026-08-20
CVE-2026-76956 libexpat 异常处理不当漏洞 CWE-394 5.9 Medium 2026-08-20
CVE-2026-66046 Expat Denial of Service via storeAtts() Quadratic Complexity CWE-407 7.5 High 2026-08-18
CVE-2026-72522 Expat 缓冲区错误漏洞 CWE-125 6.2 Medium 2026-08-10
CVE-2026-56412 libexpat project libexpat 资源管理错误漏洞 CWE-416 4.9 Medium 2026-06-21
CVE-2026-56411 libexpat project libexpat 数字错误漏洞 CWE-190 6.9 Medium 2026-06-21
CVE-2026-56410 libexpat project libexpat 数字错误漏洞 CWE-190 6.9 Medium 2026-06-21
CVE-2026-56409 libexpat project libexpat 数字错误漏洞 CWE-190 6.5 Medium 2026-06-21
CVE-2026-56408 libexpat project libexpat 数字错误漏洞 CWE-190 6.9 Medium 2026-06-21
CVE-2026-56407 libexpat project libexpat 数字错误漏洞 CWE-190 6.9 Medium 2026-06-21
CVE-2026-56406 libexpat project libexpat 数字错误漏洞 CWE-190 6.9 Medium 2026-06-21
CVE-2026-56405 libexpat project libexpat 数字错误漏洞 CWE-190 6.9 Medium 2026-06-21
CVE-2026-56404 libexpat project libexpat 数字错误漏洞 CWE-190 6.9 Medium 2026-06-21
CVE-2026-56403 libexpat project libexpat 数字错误漏洞 CWE-190 6.9 Medium 2026-06-21
CVE-2026-56132 libexpat project libexpat 竞争条件问题漏洞 CWE-821 6.9 Medium 2026-06-19
CVE-2026-56131 libexpat project libexpat 资源管理错误漏洞 CWE-416 4.9 Medium 2026-06-19
CVE-2026-50219 libexpat 资源管理错误漏洞 CWE-416 4.9 Medium 2026-06-04
CVE-2026-45186 libexpat 安全漏洞 CWE-407 2.9 Low 2026-05-10
CVE-2026-41080 libexpat 安全漏洞 CWE-331 2.9 Low 2026-04-16
CVE-2026-32778 libexpat 代码问题漏洞 CWE-476 2.9 Low 2026-03-16
CVE-2026-32777 libexpat 安全漏洞 CWE-835 4.0 Medium 2026-03-16
CVE-2026-32776 libexpat 代码问题漏洞 CWE-476 4.0 Medium 2026-03-16
CVE-2026-25210 libexpat 输入验证错误漏洞 CWE-190 6.9 Medium 2026-01-30
CVE-2026-24515 libexpat 代码问题漏洞 CWE-476 2.9 Low 2026-01-23
CVE-2025-66382 libexpat 安全漏洞 CWE-407 2.9 Low 2025-11-28
CVE-2025-59375 Expat 安全漏洞 CWE-770 7.5 High 2025-09-15

All 28 known CVE vulnerabilities affecting libexpat with full Chinese analysis, references, and POCs where available.