Libexpat
Vendor:
First CVE: Nov 3, 2009 · Active for 16 years
61
Total CVEs
More Total CVEs than 98% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libexpat over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2009
16 years ago
Most Recent CVE
Jun 21, 2026
33 days ago
CVE Severity & Scoring
Libexpat61 CVEs
46%
36%
16%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local21 (34.4%)
Network33 (54.1%)
Unknown7 (11.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (63.9%)
High15 (24.6%)
Unknown7 (11.5%)
User Interaction
None47 (77.0%)
Unknown7 (11.5%)
Required7 (11.5%)
Privileges Required
Low7 (11.5%)
High0 (0.0%)
None47 (77.0%)
Unknown7 (11.5%)
Top CVEs
Signals from CVEs in this product scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25236CRITICAL xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. | Feb 16, 2022 | 9.8 | 50 | NO | NO |
CVE-2026-45186HIGH In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. | May 10, 2026 | 7.5 | 35 | NO | NO |
CVE-2022-23852CRITICAL Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. | Jan 24, 2022 | 9.8 | 35 | NO | NO |
CVE-2009-3720MEDIUM The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a | Nov 3, 2009 | 5.0 | 35 | NO | NO |
CVE-2016-4472HIGH The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute | Jun 30, 2016 | 8.1 | 34 | NO | NO |
CVE-2026-56132MEDIUM In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sha | Jun 19, 2026 | 6.9 | 33 | NO | NO |
CVE-2022-25315CRITICAL In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. | Feb 18, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-25235CRITICAL xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. | Feb 16, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-22824CRITICAL defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | Jan 10, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-22823CRITICAL build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | Jan 10, 2022 | 9.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (61 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (61 CVEs).
Media Mentions
Signals from CVEs in this product scope (61 CVEs).
Top CNAs Publishing CVEs For Libexpat
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.2.2 | 1 | 7.8 | 0.5% | 0 | 0 |
| 2.2.1 | 1 | 7.8 | 0.5% | 0 | 0 |
| 2.0.1 | 2 | 5.0 | 26.1% | 0 | 0 |
| 2.0.0 | 2 | 4.7 | 3.1% | 0 | 0 |
| 1.95.8 | 2 | 4.7 | 3.1% | 0 | 0 |
| 1.95.7 | 2 | 4.7 | 3.1% | 0 | 0 |
| 1.95.6 | 2 | 4.7 | 3.1% | 0 | 0 |
| 1.95.5 | 2 | 4.7 | 3.1% | 0 | 0 |
| 1.95.4 | 2 | 4.7 | 3.1% | 0 | 0 |
| 1.95.2 | 2 | 4.7 | 3.1% | 0 | 0 |
| 1.95.1 | 2 | 4.7 | 3.1% | 0 | 0 |