<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3alibexpat_projectlibexpat/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 17:59:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3alibexpat_projectlibexpat/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Expat XML Parsing Library Integer Overflow Vulnerabilities</title><link>https://feed.craftedsignal.io/briefs/2026-09-expat-vulnerability/</link><pubDate>Tue, 01 Sep 2026 17:59:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-expat-vulnerability/</guid><description>The Expat XML parsing library is affected by integer overflow vulnerabilities (CVE-2022-25235, CVE-2022-25236) that can be exploited by a local attacker to achieve arbitrary code execution or denial of service.</description><content:encoded><![CDATA[<p>The Expat XML parser (libexpat) is susceptible to multiple integer overflow vulnerabilities, identified as CVE-2022-25235 and CVE-2022-25236. These flaws stem from improper handling of integer operations during XML parsing, which can be leveraged by a local attacker. Successfully triggering these overflows can result in memory corruption, potentially leading to arbitrary code execution, unauthorized information disclosure, or application-level denial-of-service conditions. Given the ubiquity of Expat as a dependency in many cross-platform applications, organizations should identify internal software suites that bundle or link against this library and ensure they are updated to a patched version that resolves these integer overflow conditions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows a local attacker to compromise the integrity and availability of applications using the vulnerable Expat library. The impact ranges from application crashes (DoS) to more severe outcomes, including the disclosure of sensitive process memory or the execution of arbitrary code within the context of the user or process running the affected application.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for infrastructure and security teams:</p>
<ul>
<li>Inventory internal software applications that utilize the Expat XML library to determine exposure.</li>
<li>Apply patches provided by the software vendor or the operating system maintainer for libexpat to address CVE-2022-25235 and CVE-2022-25236.</li>
<li>Monitor application crash logs for frequent or irregular termination of services that process XML data, as these may indicate exploitation attempts or memory corruption issues.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>