{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alibexpat_projectlibexpat/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*","cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2022-25235"},{"cvss":9.8,"id":"CVE-2022-25236"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["expat (\u003c 2.4.5)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Libexpat"],"content_html":"\u003cp\u003eThe Expat XML parser (libexpat) is susceptible to multiple integer overflow vulnerabilities, identified as CVE-2022-25235 and CVE-2022-25236. These flaws stem from improper handling of integer operations during XML parsing, which can be leveraged by a local attacker. Successfully triggering these overflows can result in memory corruption, potentially leading to arbitrary code execution, unauthorized information disclosure, or application-level denial-of-service conditions. Given the ubiquity of Expat as a dependency in many cross-platform applications, organizations should identify internal software suites that bundle or link against this library and ensure they are updated to a patched version that resolves these integer overflow conditions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows a local attacker to compromise the integrity and availability of applications using the vulnerable Expat library. The impact ranges from application crashes (DoS) to more severe outcomes, including the disclosure of sensitive process memory or the execution of arbitrary code within the context of the user or process running the affected application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for infrastructure and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eInventory internal software applications that utilize the Expat XML library to determine exposure.\u003c/li\u003e\n\u003cli\u003eApply patches provided by the software vendor or the operating system maintainer for libexpat to address CVE-2022-25235 and CVE-2022-25236.\u003c/li\u003e\n\u003cli\u003eMonitor application crash logs for frequent or irregular termination of services that process XML data, as these may indicate exploitation attempts or memory corruption issues.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T17:59:30Z","date_published":"2026-09-01T17:59:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-expat-vulnerability/","summary":"The Expat XML parsing library is affected by integer overflow vulnerabilities (CVE-2022-25235, CVE-2022-25236) that can be exploited by a local attacker to achieve arbitrary code execution or denial of service.","title":"Expat XML Parsing Library Integer Overflow Vulnerabilities","url":"https://feed.craftedsignal.io/briefs/2026-09-expat-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}