Known Vulnerabilities for Libexpat by Libexpat Project
Listed below are 10 of the newest known vulnerabilities associated with "Libexpat" by "Libexpat Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56412 json | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for v... | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56411 json | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56410 json | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56409 json | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56408 json | libexpat before 2.8.2 has an integer overflow in copyString. | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56407 json | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56406 json | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56405 json | libexpat before 2.8.2 has an integer overflow in getAttributeId. | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56404 json | libexpat before 2.8.2 has an integer overflow in addBinding. | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56403 json | libexpat before 2.8.2 has an integer overflow in storeAtts. | Not Provided | 2026-06-21 | 2026-06-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Libexpat Project | Libexpat | 2.2.9 | |||
| Application | Libexpat Project | Libexpat | 2.2.8 | |||
| Application | Libexpat Project | Libexpat | 2.2.7 | |||
| Application | Libexpat Project | Libexpat | 2.2.6 | |||
| Application | Libexpat Project | Libexpat | 2.2.5 | |||
| Application | Libexpat Project | Libexpat | 2.2.4 | |||
| Application | Libexpat Project | Libexpat | 2.2.3 | |||
| Application | Libexpat Project | Libexpat | 2.2.2 | |||
| Application | Libexpat Project | Libexpat | 2.2.10 | |||
| Application | Libexpat Project | Libexpat | 2.2.1 | |||
| Application | Libexpat Project | Libexpat | 2.2.0 | |||
| Application | Libexpat Project | Libexpat | 2.1.1 | |||
| Application | Libexpat Project | Libexpat | 2.1.0 | |||
| Application | Libexpat Project | Libexpat | 2.0.1 | |||
| Application | Libexpat Project | Libexpat | 2.0.0 | |||
| Application | Libexpat Project | Libexpat | 1.95.8 | |||
| Application | Libexpat Project | Libexpat | 1.95.7 | |||
| Application | Libexpat Project | Libexpat | 1.95.6 | |||
| Application | Libexpat Project | Libexpat | 1.95.5 | |||
| Application | Libexpat Project | Libexpat | 1.95.4 |