CVE-2026-32777

Name
CVE-2026-32777
Description
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/libexpat/libexpat/issues/1161
cve@mitre.org https://github.com/libexpat/libexpat/pull/1159
cve@mitre.org https://github.com/libexpat/libexpat/pull/1162
cve@mitre.org https://issues.oss-fuzz.com/issues/486993411

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* libexpat >= None < 2.7.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
expat edge-main 2.7.5-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.23-main 2.7.5-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.22-main 2.7.5-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.21-main 2.7.5-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
expat 3.20-main 2.7.5-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed