Vulnerabilidades en libexpat project
26 resultadosAnálisis Vexday
O libexpat registra 22 vulnerabilidades totais, com preocupação significativa: 14 publicadas nos últimos 90 dias indicam descobertas ativas e recentes. Embora nenhuma esteja sob exploração confirmada (KEV) e nenhuma seja crítica em CVSS, a fraqueza dominante em overflow de inteiros (CWE-190) representa risco de negação de serviço e potencial corrupção de memória em aplicações que dependem da biblioteca. A velocidade de descobertas recomenda revisão de atualizações do projeto.
CVE-2026-56410MEDIUMxmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.EPSS 0.1%CVE-2026-56412MEDIUMlibexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls frEPSS 0.1%CVE-2026-50219MEDIUMlibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParseEPSS 0.1%CVE-2026-56409MEDIUMxmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.EPSS 0.1%CVE-2026-56131MEDIUMlibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. TEPSS 0.1%CVE-2026-56132MEDIUMIn libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is misEPSS 0.1%