Integer Overflow Vulnerability in libexpat Versions from Vendor
CVE-2026-102633
8.2HIGH
What is CVE-2026-102633?
Versions of libexpat from 2.7.2 to 2.8.5 are susceptible to an integer overflow vulnerability within the expat_realloc() function, particularly on 32-bit systems. This flaw arises during the calculation of allocation sizes. Malicious actors can exploit this vulnerability by delivering crafted XML content to applications that utilize the affected libexpat versions. Successful exploitation could lead to heap buffer overflows, ultimately resulting in memory corruption or even a denial of service condition within the application.
Affected Version(s)
libexpat 2.7.2 <= 2.8.5
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Filippo Tedeschi
Matthew Fernandez
Filippo Tedeschi
