Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-102633

MEDIUM NVD
CVSS Score 5.9
Severity MEDIUM
Published Sep 29, 2026
Vendor unknown

Description

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.

References