Junglewise Threat Intelligence

CVE-2025-66382: libexpat inefficient algorithmic complexity denial of service

CVE-2025-66382 · Severity: low · CVSS 2.9 · Published 2025-11-28

Technologies: libexpat Project libexpat, Siemens SINEC OS (RUGGEDCOM RST2428P), Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU family. Vendors: Libexpat Project, Siemens.

Executive brief

libexpat is a widely used software library for processing XML data, found in many operating systems and industrial devices. A vulnerability has been identified where a specially crafted, relatively small file (approx. 2 MiB) can cause the library to consume excessive processing time. This can lead to a denial-of-service condition, making the affected application or device unresponsive for significant periods, potentially disrupting business operations or industrial processes.

Technical details

A vulnerability exists in libexpat through version 2.7.3 due to inefficient algorithmic complexity (CWE-407) when parsing certain XML structures. An attacker can provide a crafted XML file of approximately 2 MiB that requires 25 to 100 seconds of CPU time to process, depending on the hardware. This local attack vector typically requires a user to open the malicious file or for an application to process untrusted input using the library. While NVD assigned a medium severity (5.5) based on high availability impact, the vendor (MITRE) initially reported it as low (2.9). Siemens has acknowledged impact on SIMATIC S7-1500 and SINEC OS products. As of the advisory date, a formal patch in the libexpat master branch was still pending.

Affected products

  • libexpat project libexpat up to and including 2.7.3
  • Siemens SIMATIC S7-1500 CPU family versions >= V3.1.5
  • Siemens SINEC OS (RUGGEDCOM RST2428P) versions < V4.0

Timeline

  • 2025-09-25: other: Vulnerability reported to developers by a researcher
  • 2025-10-04: other: Public issue opened on GitHub tracking the flaw
  • 2025-11-28: disclosed: CVE published
  • 2026-06-02: patched: Siemens released SINEC OS V4.0 containing a fix

References

Related threats