OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-102633 (CVSS 8.2)

NVD · officialPublished Sep 29, 2026Risk 37/100

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.

CVSS
8.2
AV:NetworkAC:HighPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source