Libexpat is a compact, widely embedded XML parsing library that sits deep in the software supply chain across countless servers, applications, and systems despite maintaining a single product focus. Vulnerabilities affecting the library skew toward serious outcomes, with a notable share reaching critical severity, and their impact propagates to every downstream product that incorporates Libexpat, amplifying the practical importance of individual flaws. The recurring weakness classes—including integer overflows, improper XML external entity handling, buffer-boundary violations, XML entity expansion attacks, and NULL-pointer dereferences—reflect the parsing complexity and state-machine demands inherent to XML processing. Defenders should prioritize tracking products that bundle Libexpat rather than the library alone, since remediation often depends on downstream vendors rebuilding and releasing updates. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libexpat Project over time
Signals from CVEs in this vendor scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25236CRITICAL xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. | Feb 16, 2022 | 9.8 | 50 | NO | NO |
CVE-2026-45186HIGH In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. | May 10, 2026 | 7.5 | 35 | NO | NO |
CVE-2022-23852CRITICAL Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. | Jan 24, 2022 | 9.8 | 35 | NO | NO |
CVE-2009-3720MEDIUM The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a | Nov 3, 2009 | 5.0 | 35 | NO | NO |
CVE-2016-4472HIGH The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute | Jun 30, 2016 | 8.1 | 34 | NO | NO |
CVE-2026-56132MEDIUM In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sha | Jun 19, 2026 | 6.9 | 33 | NO | NO |
CVE-2022-25315CRITICAL In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. | Feb 18, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-25235CRITICAL xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. | Feb 16, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-22824CRITICAL defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | Jan 10, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-22823CRITICAL build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | Jan 10, 2022 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (61 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libexpat Project.
Media articles that mention a CVE ID that affects a product developed by Libexpat Project — matched by CVE ID, not by vendor name.