Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-8176

28
FAUCET Score

CVE-2024-8176 is a stack overflow vulnerability in the libexpat library, affecting products that use it for XML parsing, such as Hitachi Energy RTU500 and Apple iOS/macOS. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated attacker to trigger a denial of service or potentially memory corruption by crafting XML documents with deeply nested entity references. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Enterprise Linux 8
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat OpenShift Container Platform 4
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9.0 Update Services For SAP Solutions
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9.2 Update Services For SAP Solutions
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.57%
Probability of exploitation in next 30 days
EPSS Percentile
72.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0157 is in the 55th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (44)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
gcppatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 17470-17084Fixed in: 2.6.4-1
microsoftpatch availablevia msrc
Product: 20210-17086Fixed in: 2.6.4-1
microsoftpatch availablevia msrc
Product: azl3 expat 2.6.4-1 on Azure Linux 3.0Fixed in: 2.6.4-1
microsoftpatch availablevia msrc
Product: cbl2 expat 2.6.4-1 on CBL Mariner 2.0Fixed in: 2.6.4-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: xmlrpc-c-0:1.51.0-5.el8_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: xmlrpc-c-0:1.51.0-5.el8_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: expat-0:2.2.10-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: xmlrpc-c-0:1.51.0-6.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: expat-0:2.2.10-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: xmlrpc-c-0:1.51.0-6.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: expat-0:2.2.10-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: xmlrpc-c-0:1.51.0-6.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: xmlrpc-c-0:1.51.0-8.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: expat-0:2.2.10-1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: expat-0:2.2.10-1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: expat-0:2.5.0-3.el9_5.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: expat-0:2.5.0-5.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: expat-0:2.2.10-12.el9_0.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: expat-0:2.5.0-1.el9_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: expat-0:2.5.0-2.el9_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Core Services 2.4.62.SP1Fixed in: expat
View patch
redhatpatch availablevia redhat_api
Product: DevWorkspace Operator 0.33Fixed in: devworkspace/devworkspace-project-clone-rhel9:sha256:9cde560029ea98eb500a811c82e4d55318d686e01383c00e857b838a2db88919
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 1.14Fixed in: discovery/discovery-server-rhel9:sha256:ad1045aa0de937c3a6969ec377f7bfeda9a44ee434a954e8245e9840316ffc1c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: expat-0:2.7.1-1.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 1.14Fixed in: discovery/discovery-ui-rhel9:sha256:c960fa13577db72b52765d6941688f431f61fe38adb717b2d8bb6569e241bc5e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: expat-0:2.2.5-17.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: xmlrpc-c-0:1.51.0-11.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: expat-0:2.2.10-1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: xmlrpc-c-0:1.51.0-5.el8_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: expat-0:2.2.10-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: xmlrpc-c-0:1.51.0-5.el8_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: expat-0:2.2.10-1.el8_4
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mingw-expat
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: thunderbird:flatpak/thunderbird
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: thunderbird
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: firefox:flatpak/firefox
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: firefox
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: thunderbird
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: firefox

Vendor Advisories (6)

gcpllm-gcp-251ac0c885af6b4bCRITICAL

Certain HP LaserJet Enterprise and HP LaserJet Managed Printers – Potential Denial of Service & Potential Buffer Overflow

Feb 25, 2026
honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2024-8176Moderate

libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat

Mar 13, 2025
microsoft2025-Mar/CVE-2024-8176Important

Libexpat: expat: improper restriction of xml entity expansion depth in libexpat

Mar 11, 2025

References

blog.hartwork.org / posts/expat-2-7-0-released
bugzilla.suse.com / show_bug.cgi
seclists.org / fulldisclosure/2025/May/10
seclists.org / fulldisclosure/2025/May/11
seclists.org / fulldisclosure/2025/May/12
seclists.org / fulldisclosure/2025/May/6
seclists.org / fulldisclosure/2025/May/7
seclists.org / fulldisclosure/2025/May/8
github.com / libexpat/libexpat/blob/R_2_7_0/expat/Changes
gitlab.alpinelinux.org / alpine/aports/-/commit/d068c3ff36fc6f4789988a09c69b434db757db53
security.netapp.com / advisory/ntap-20250328-0009
security-tracker.debian.org / tracker/CVE-2024-8176
ubuntu.com / security/CVE-2024-8176
kb.cert.org / vuls/id/760160
openwall.com / lists/oss-security/2025/03/15/1
openwall.com / lists/oss-security/2025/09/24/11
access.redhat.com / errata/RHSA-2025:13681
access.redhat.com / errata/RHSA-2025:22033
access.redhat.com / errata/RHSA-2025:22034
access.redhat.com / errata/RHSA-2025:22035
access.redhat.com / errata/RHSA-2025:22607
access.redhat.com / errata/RHSA-2025:22785
access.redhat.com / errata/RHSA-2025:22842
access.redhat.com / errata/RHSA-2025:22871
access.redhat.com / errata/RHSA-2025:3531
access.redhat.com / errata/RHSA-2025:3734
access.redhat.com / errata/RHSA-2025:3913
access.redhat.com / errata/RHSA-2025:4048
access.redhat.com / errata/RHSA-2025:4446
access.redhat.com / errata/RHSA-2025:4447
access.redhat.com / errata/RHSA-2025:4448
access.redhat.com / errata/RHSA-2025:4449
access.redhat.com / errata/RHSA-2025:7444
access.redhat.com / errata/RHSA-2025:7512
access.redhat.com / errata/RHSA-2025:8385
access.redhat.com / security/cve/CVE-2024-8176
bugzilla.redhat.com / show_bug.cgi
github.com / libexpat/libexpat/issues/893
github.com / libexpat/libexpat/pull/973