Vendor
high
advisory
Expat UTF-16 Improper Surrogate Validation Vulnerability
1 CVEThe Expat library through version 2.8.4 incorrectly validates UTF-16 surrogate pairs, allowing attackers to perform XML injection via malformed input that obscures markup characters.
Expat
1c
medium
advisory
Expat XML Parsing Library Integer Overflow Vulnerabilities
1 TTP 2 CVEsThe Expat XML parsing library is affected by integer overflow vulnerabilities (CVE-2022-25235, CVE-2022-25236) that can be exploited by a local attacker to achieve arbitrary code execution or denial of service.
expat
1t
2c
low
advisory
Expat Denial of Service Vulnerability (CVE-2026-66046)
1 CVEThe Expat library through version 2.8.3 contains an algorithmic complexity vulnerability in its XML attribute parsing logic that allows unauthenticated attackers to cause CPU exhaustion and denial of service.
Expat
denial-of-service
vulnerability
cve-2026-66046
1c