PT-2025-46012 · Julia · Expat Jll

Published

2025-10-14

·

Updated

2025-10-14

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML GetCurrentLineNumber (or XML GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2025-41

Affected Products

Expat Jll