CVE-2026-25210

I

n libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

Configurations

No configuration.

History

04 Feb 2026, 16:34

Type Values Removed Values Added
Summary
  • (es) En libexpat antes de 2.7.4, la función doContent no determina correctamente el tamaño del búfer bufSize porque no hay una comprobación de desbordamiento de entero para la reasignación del búfer de etiquetas.

30 Jan 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 07:16

Updated : 2026-02-04 16:34


NVD link : CVE-2026-25210

Mitre link : CVE-2026-25210

CVE.ORG link : CVE-2026-25210


JSON object : View

Products Affected

No product.

CWE
CWE-190

Integer Overflow or Wraparound