oss-sec mailing list archives

libexpat 2.9.0 fixes two vulnerabilities


From: Sebastian Pipping <sebastian () pipping org>
Date: Mon, 5 Oct 2026 20:18:10 +0200

Hello oss-security,


just a quick note that libexpat 2.9.0 (or "Expat 2.9.0") released today
is fixing two vulnerabilities:

- CVE-2026-77214
- CVE-2026-102633

The related part of the change log is this:

  #1392  CVE-2026-102633 -- Integer overflow in function expat_realloc
           on 32bit platforms
  #1393  CVE-2026-77214 -- Validate parameter `len` against available
           buffer capacity in XML_ParseBuffer

Some key links are:

- The blog post about it
  https://blog.hartwork.org/posts/expat-2-9-0-released/

- The full change log of release 2.9.0
  https://github.com/libexpat/libexpat/blob/R_2_9_0/expat/Changes

- The fixing pull requests
  - https://github.com/libexpat/libexpat/pull/1392
  - https://github.com/libexpat/libexpat/pull/1393

- The NVD CVE metadata
  - https://nvd.nist.gov/vuln/detail/cve-2026-77214
  - https://nvd.nist.gov/vuln/detail/cve-2026-102633

Best



Sebastian


Current thread: