Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-43680

25
FAUCET Score

CVE-2022-43680 is a use-after-free vulnerability in libexpat versions up to 2.4.9, affecting products like Debian, Fedora, and NetApp, caused by premature destruction of shared DTDs during out-of-memory conditions. Rated 7.5 HIGH, it allows unauthenticated attackers to achieve denial of service with low attack complexity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion, indicating a low current threat level.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.4.9CPE matchmatch criteria
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.26%
Probability of exploitation in next 30 days
EPSS Percentile
81.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0226 is in the 66th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (33)

bitdefenderpatch availablevia llm_extracted
Fixed in: ['9.0.2303.100']
View patch
denopatch availablevia llm_extracted
Fixed in: 4.1.15
View patch
github_advisorypatch availablevia nvd_reference
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 4.1.15
View patch
microsoftpatch availablevia msrc
Product: cbl2 expat 2.5.0-1 on CBL Mariner 2.0Fixed in: 2.5.0-1
microsoftpatch availablevia msrc
Product: 18575-16820Fixed in: 2.5.0-1
microsoftpatch availablevia msrc
Product: 18576-16823Fixed in: 2.5.0-1
microsoftpatch availablevia msrc
Product: cm1 expat 2.5.0-1 on CBL Mariner 1.0Fixed in: 2.5.0-1
nessuspatch availablevia llm_extracted
Fixed in: 4.1.15
postgresqlpatch availablevia llm_extracted
Fixed in: 4.1.15
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: firefox-0:102.5.0-1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: expat-0:2.2.10-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: firefox-0:102.5.0-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: expat-0:2.2.10-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: firefox-0:102.5.0-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: expat-0:2.2.5-8.el8_6.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: expat-0:2.4.9-1.el9_1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: expat-0:2.2.10-1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: firefox-0:102.5.0-1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: firefox-0:102.5.0-1.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: expat-0:2.2.5-10.el8_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: firefox-0:102.5.0-1.el8_7
View patch
redhatpatch availablevia redhat_api
Product: JBCS httpd 2.4.51.sp2Fixed in: expat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: firefox-0:102.5.0-1.el8_2
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: firefox:flatpak/firefox
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: thunderbird:flatpak/thunderbird
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: firefox
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: firefox
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: thunderbird
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: thunderbird
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: thunderbird
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: expat
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: thunderbird:flatpak/thunderbird

Vendor Advisories (7)

bitdefenderllm-bitdefender-b23af70584e80d8cHIGH

June Third Party Package Updates in Splunk Cloud

Jun 1, 2023
redhatCVE-2022-43680Moderate

expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate

Oct 24, 2022
microsoft2022-Oct/CVE-2022-43680Important

In libexpat through 2.4.9 there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

Oct 11, 2022
nessusllm-nessus-13d356354de17dcb

"Use after free" fixed in expat >= 2.4.9

denollm-deno-c256b608e300fb40

"Use after free" fixed in expat >= 2.4.9

postgresqlllm-postgresql-e5e45ee1a9088dcd

"Use after free" fixed in expat >= 2.4.9

libreofficellm-libreoffice-6a0ce202f293609d

"Use after free" fixed in expat >= 2.4.9

References

github.com / libexpat/libexpat/issues/649
ExploitIssue TrackingPatchThird Party Advisory
github.com / libexpat/libexpat/pull/616
ExploitIssue TrackingPatchThird Party Advisory
github.com / libexpat/libexpat/pull/650
ExploitIssue TrackingPatchThird Party Advisory
lists.debian.org / debian-lts-announce/2022/10/msg00033.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BY4OPSIB33ETNUXZY2UPZ4NGQ3OKDY4D
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/DPQVIF6TOJNY2T3ZZETFKR4G34FFREBQ
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FFCOMBSOJKLIKCGCJWHLJXO4EVYBG7AR
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/IUJ2BULJTZ2BMSKQHB6US674P55UCWWS
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/XG5XOOB7CD55CEE6OJYKSACSIMQ4RWQ6
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202210-38
Third Party Advisory
security.netapp.com / advisory/ntap-20221118-0007
Third Party Advisory
debian.org / security/2022/dsa-5266
Third Party Advisory
openwall.com / lists/oss-security/2023/12/28/5
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2024/01/03/5
Mailing ListThird Party Advisory