Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libexpat Project

First CVE: Nov 3, 2009Active for: 17 yearsTotal CVEs: 61
44.9
VTI Score
High

Libexpat is a compact, widely embedded XML parsing library that sits deep in the software supply chain across countless servers, applications, and systems despite maintaining a single product focus. Vulnerabilities affecting the library skew toward serious outcomes, with a notable share reaching critical severity, and their impact propagates to every downstream product that incorporates Libexpat, amplifying the practical importance of individual flaws. The recurring weakness classes—including integer overflows, improper XML external entity handling, buffer-boundary violations, XML entity expansion attacks, and NULL-pointer dereferences—reflect the parsing complexity and state-machine demands inherent to XML processing. Defenders should prioritize tracking products that bundle Libexpat rather than the library alone, since remediation often depends on downstream vendors rebuilding and releasing updates. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
61
Total CVEs
More Total CVEs than 99% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libexpat Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2009
16 years ago
Most Recent CVE
Jun 21, 2026
33 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (61 CVEs).

61 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-25236CRITICAL
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
Feb 16, 20229.850NONO
CVE-2026-45186HIGH
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
May 10, 20267.535NONO
CVE-2022-23852CRITICAL
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
Jan 24, 20229.835NONO
CVE-2009-3720MEDIUM
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a
Nov 3, 20095.035NONO
CVE-2016-4472HIGH
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute
Jun 30, 20168.134NONO
CVE-2026-56132MEDIUM
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sha
Jun 19, 20266.933NONO
CVE-2022-25315CRITICAL
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
Feb 18, 20229.833NONO
CVE-2022-25235CRITICAL
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
Feb 16, 20229.833NONO
CVE-2022-22824CRITICAL
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Jan 10, 20229.833NONO
CVE-2022-22823CRITICAL
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Jan 10, 20229.833NONO
View all 61 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products61 CVEs
46%
36%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local21 (34.4%)
Network33 (54.1%)
Unknown7 (11.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (63.9%)
High15 (24.6%)
Unknown7 (11.5%)
User Interaction
None47 (77.0%)
Unknown7 (11.5%)
Required7 (11.5%)
Privileges Required
Low7 (11.5%)
High0 (0.0%)
None47 (77.0%)
Unknown7 (11.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (61 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libexpat Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libexpat Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libexpat Project's Products

View all 4 CNAs →

Top CWEs