CVE-2026-25210

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

History

10 Mar 2026, 18:17

Type Values Removed Values Added
CPE cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*
First Time Libexpat Project libexpat
Libexpat Project
References () https://github.com/libexpat/libexpat/pull/1075 - () https://github.com/libexpat/libexpat/pull/1075 - Issue Tracking, Patch
References () https://github.com/libexpat/libexpat/pull/1075/commits/9c2d990389e6abe2e44527eeaa8b39f16fe859c7 - () https://github.com/libexpat/libexpat/pull/1075/commits/9c2d990389e6abe2e44527eeaa8b39f16fe859c7 - Patch

04 Feb 2026, 16:34

Type Values Removed Values Added
Summary
  • (es) En libexpat antes de 2.7.4, la función doContent no determina correctamente el tamaño del búfer bufSize porque no hay una comprobación de desbordamiento de entero para la reasignación del búfer de etiquetas.

30 Jan 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 07:16

Updated : 2026-03-10 18:17


NVD link : CVE-2026-25210

Mitre link : CVE-2026-25210

CVE.ORG link : CVE-2026-25210


JSON object : View

Products Affected

libexpat_project

  • libexpat
CWE
CWE-190

Integer Overflow or Wraparound