Vendor
The Expat library through version 2.8.3 contains an algorithmic complexity vulnerability in its XML attribute parsing logic that allows unauthenticated attackers to cause CPU exhaustion and denial of service.