CVE-2025-66382

EUVD-2025-199862
In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.9 LOW
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
mitreCNA
2.9 LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
Affected Products (NVD)
VendorProductVersion
libexpat_projectlibexpat
𝑥
≤ 2.7.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
expat
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
expat
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
plucky
ignored
questing
deferred
trusty
deferred
xenial
deferred
apache2
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected
trusty
not-affected
xenial
not-affected
apr-util
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected
trusty
not-affected
xenial
not-affected
cmake
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected
xenial
not-affected
ghostscript
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected
xenial
not-affected
texlive-bin
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected
xenial
not-affected
xmlrpc-c
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
needs-triage
trusty
needs-triage
xenial
needs-triage
vnc4
bionic
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
trusty
needs-triage
xenial
needs-triage
wbxml2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
needs-triage
xenial
needs-triage
swish-e
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
needs-triage
xenial
needs-triage
insighttoolkit4
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
plucky
dne
questing
dne
xenial
needs-triage
cadaver
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
needs-triage
xenial
needs-triage
gdcm
bionic
needs-triage
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected
trusty
not-affected
xenial
needs-triage
ayttm
jammy
dne
noble
dne
plucky
dne
questing
dne
xenial
needs-triage
cableswig
jammy
dne
noble
dne
plucky
dne
questing
dne
xenial
needs-triage
coin3
bionic
needs-triage
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected
trusty
needs-triage
xenial
needs-triage
matanza
bionic
needs-triage
focal
ignored
jammy
ignored
noble
ignored
plucky
ignored
questing
ignored
xenial
needs-triage
tdom
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
needs-triage
xenial
needs-triage
vtk
jammy
dne
noble
dne
plucky
dne
questing
dne
trusty
needs-triage
xenial
needs-triage
smart
bionic
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
xenial
needs-triage
firefox
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected
thunderbird
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected
libxmltok
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
dne
xenial
needs-triage