CVE-2019-15903: Libexpat Project Libexpat
High severity, CVSS 7.5. EPSS: 6.6% chance of exploitation in the next 30 days.
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
Affected products
- Libexpat Project Libexpat: before 2.2.8 (fixed in 2.2.8)
- Python Python: from 2.7.0, before 2.7.17 (fixed in 2.7.17); from 3.5.0, before 3.5.8 (fixed in 3.5.8); from 3.6.0, before 3.6.10 (fixed in 3.6.10); from 3.7.0, before 3.7.5 (fixed in 3.7.5)
Published 2019-09-04. Last modified 2026-06-17.