Home

Description

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

PUBLISHED Reserved 2025-09-15 | Published 2025-09-15 | Updated 2025-09-17 | Assigner mitre




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:H/RL:T/RC:C

Problem types

CWE-770 Allocation of Resources Without Limits or Throttling

Product status

Default status
unaffected

Any version before 2.7.2
affected

References

github.com/libexpat/libexpat/issues/1018

github.com/libexpat/libexpat/pull/1034

github.com/...1ec768732fac215da9730b5f50fbd2bf/expat/Changes

issues.oss-fuzz.com/issues/439133977

github.com/libexpat/libexpat/blob/R_2_7_2/expat/Changes

cve.org (CVE-2025-59375)

nvd.nist.gov (CVE-2025-59375)

Download JSON