CVE-2026-24515: Libexpat Project Libexpat
Low severity, CVSS 2.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
Affected products
- Libexpat Project Libexpat: before 2.7.4 (fixed in 2.7.4)
Published 2026-01-23. Last modified 2026-06-17.