JLSEC-2025-173
Dashboard / Vulnerabilities / JLSEC-2025-173
Summary: libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a...
Details: libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
References: http://www.openwall.com/lists/oss-security/2025/09/16/2, http://www.openwall.com/lists/oss-security/2026/05/01/5, https://cert-portal.siemens.com/productcert/html/ssa-082556.html, https://cert-portal.siemens.com/productcert/html/ssa-089022.html, https://github.com/libexpat/libexpat/blob/676a4c531ec768732fac215da9730b5f50fbd2bf/expat/Changes#L45-L74, https://github.com/libexpat/libexpat/blob/R_2_7_2/expat/Changes, https://github.com/libexpat/libexpat/issues/1018, https://github.com/libexpat/libexpat/pull/1034, https://issues.oss-fuzz.com/issues/439133977
Affected packages
Package
Name: Expat_jll
Purl: pkg:julia/Expat_jll?uuid=2e619515-83b5-522b-bb60-26c02a35a201
Affected ranges
Type: SEMVER
Events:
