CVE 6.9 MEDIUM

CVE-2026-25210_CVE-2026-25210

6.9 / 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Description

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

Basic Information

ID CVE-2026-25210
Source mitre
Published Jan 30, 2026 at 06:40
Modified Jan 30, 2026 at 07:21

Affected Product

Vendor libexpat project
Product libexpat
Affected Versions libexpat project libexpat 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.