CVE-2026-25210

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-30 07:16

Updated : 2026-01-30 07:16


NVD link : CVE-2026-25210

Mitre link : CVE-2026-25210

CVE.ORG link : CVE-2026-25210


JSON object : View

Products Affected

No product.

CWE
CWE-190

Integer Overflow or Wraparound