Executive brief
libexpat is a widely used software library for processing XML data, found in many operating systems and industrial devices. A vulnerability has been identified where a specially crafted, relatively small file (approx. 2 MiB) can cause the library to consume excessive processing time. This can lead to a denial-of-service condition, making the affected application or device unresponsive for significant periods, potentially disrupting business operations or industrial processes.
Technical details
A vulnerability exists in libexpat through version 2.7.3 due to inefficient algorithmic complexity (CWE-407) when parsing certain XML structures. An attacker can provide a crafted XML file of approximately 2 MiB that requires 25 to 100 seconds of CPU time to process, depending on the hardware. This local attack vector typically requires a user to open the malicious file or for an application to process untrusted input using the library. While NVD assigned a medium severity (5.5) based on high availability impact, the vendor (MITRE) initially reported it as low (2.9). Siemens has acknowledged impact on SIMATIC S7-1500 and SINEC OS products. As of the advisory date, a formal patch in the libexpat master branch was still pending.
Affected products
- libexpat project libexpat up to and including 2.7.3
- Siemens SIMATIC S7-1500 CPU family versions >= V3.1.5
- Siemens SINEC OS (RUGGEDCOM RST2428P) versions < V4.0
Timeline
- 2025-09-25: other: Vulnerability reported to developers by a researcher
- 2025-10-04: other: Public issue opened on GitHub tracking the flaw
- 2025-11-28: disclosed: CVE published
- 2026-06-02: patched: Siemens released SINEC OS V4.0 containing a fix