CVE-2026-102633: Libexpat
Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.
libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.
Affected products
- Libexpat Libexpat: from 2.7.2, up to and including 2.8.5
Published 2026-09-29. Last modified 2026-09-29.