Vulnerability Details CVE-2026-25210
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.3%
CVSS Severity
CVSS v3 Score 6.9
Products affected by CVE-2026-25210
-
cpe:2.3:a:libexpat_project:libexpat:-
-
cpe:2.3:a:libexpat_project:libexpat:1.95.0
-
cpe:2.3:a:libexpat_project:libexpat:1.95.1
-
cpe:2.3:a:libexpat_project:libexpat:1.95.2
-
cpe:2.3:a:libexpat_project:libexpat:1.95.3
-
cpe:2.3:a:libexpat_project:libexpat:1.95.4
-
cpe:2.3:a:libexpat_project:libexpat:1.95.5
-
cpe:2.3:a:libexpat_project:libexpat:1.95.6
-
cpe:2.3:a:libexpat_project:libexpat:1.95.7
-
cpe:2.3:a:libexpat_project:libexpat:1.95.8
-
cpe:2.3:a:libexpat_project:libexpat:2.0.0
-
cpe:2.3:a:libexpat_project:libexpat:2.0.1
-
cpe:2.3:a:libexpat_project:libexpat:2.1.0
-
cpe:2.3:a:libexpat_project:libexpat:2.1.1
-
cpe:2.3:a:libexpat_project:libexpat:2.2.0
-
cpe:2.3:a:libexpat_project:libexpat:2.2.1
-
cpe:2.3:a:libexpat_project:libexpat:2.2.10
-
cpe:2.3:a:libexpat_project:libexpat:2.2.2
-
cpe:2.3:a:libexpat_project:libexpat:2.2.3
-
cpe:2.3:a:libexpat_project:libexpat:2.2.4
-
cpe:2.3:a:libexpat_project:libexpat:2.2.5
-
cpe:2.3:a:libexpat_project:libexpat:2.2.6
-
cpe:2.3:a:libexpat_project:libexpat:2.2.7
-
cpe:2.3:a:libexpat_project:libexpat:2.2.8
-
cpe:2.3:a:libexpat_project:libexpat:2.2.9
-
cpe:2.3:a:libexpat_project:libexpat:2.3.0
-
cpe:2.3:a:libexpat_project:libexpat:2.4.0
-
cpe:2.3:a:libexpat_project:libexpat:2.4.1
-
cpe:2.3:a:libexpat_project:libexpat:2.4.3
-
cpe:2.3:a:libexpat_project:libexpat:2.4.4
-
cpe:2.3:a:libexpat_project:libexpat:2.4.5
-
cpe:2.3:a:libexpat_project:libexpat:2.4.6
-
cpe:2.3:a:libexpat_project:libexpat:2.4.7
-
cpe:2.3:a:libexpat_project:libexpat:2.4.8
-
cpe:2.3:a:libexpat_project:libexpat:2.4.9
-
cpe:2.3:a:libexpat_project:libexpat:2.5.0
-
cpe:2.3:a:libexpat_project:libexpat:2.6.0
-
cpe:2.3:a:libexpat_project:libexpat:2.6.1
-
cpe:2.3:a:libexpat_project:libexpat:2.6.2
-
cpe:2.3:a:libexpat_project:libexpat:2.6.3
-
cpe:2.3:a:libexpat_project:libexpat:2.6.4
-
cpe:2.3:a:libexpat_project:libexpat:2.7.0
-
cpe:2.3:a:libexpat_project:libexpat:2.7.1
-
cpe:2.3:a:libexpat_project:libexpat:2.7.2
-
cpe:2.3:a:libexpat_project:libexpat:2.7.3