Executive brief
libexpat is a widely used software library for parsing XML data. A vulnerability in how it handles internal data structures could allow an attacker to cause an integer overflow, potentially leading to data corruption or unauthorized access to information. This affects applications that rely on libexpat to process untrusted XML input.
Technical details
An integer overflow vulnerability (CWE-190) exists in libexpat's `addBinding` function in `xmlparse.c`. The flaw occurs when calculating the length of a URI, specifically during a post-increment operation (`len++`) when a namespace separator is present. While URI lengths are currently bounded by pool block sizes, the signed integer increment can trigger undefined behavior at the boundary. An attacker could potentially exploit this to cause memory corruption or information disclosure. The issue is fixed in version 2.8.2.
Affected products
- libexpat project libexpat before 2.8.2
Timeline
- 2026-05-28: other: Fix proposed in pull request
- 2026-05-29: patched: Fix merged into master branch
- 2026-06-21: disclosed: CVE published