CVE-2026-32777

EUVD-2026-12349
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
libexpat_projectlibexpat
𝑥
< 2.7.5
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
expat
suse enterprise desktop 15 SP7
2.7.1-150700.3.12.1
fixed
suse enterprise sap 15 SP4
2.7.1-150400.3.37.1
fixed
suse enterprise sap 15 SP5
2.7.1-150400.3.37.1
fixed
suse enterprise sap 15 SP7
2.7.1-150700.3.12.1
fixed
suse enterprise server 12 SP3
2.7.1-21.52.1
fixed
suse enterprise server 12 SP5
2.7.1-21.52.1
fixed
suse enterprise server 15 SP4
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP5
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP6
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP7
2.7.1-150700.3.12.1
fixed
libexpat-devel
suse enterprise desktop 15 SP7
2.7.1-150700.3.12.1
fixed
suse enterprise sap 15 SP4
2.7.1-150400.3.37.1
fixed
suse enterprise sap 15 SP5
2.7.1-150400.3.37.1
fixed
suse enterprise sap 15 SP7
2.7.1-150700.3.12.1
fixed
suse enterprise server 12 SP5
2.7.1-21.52.1
fixed
suse enterprise server 15 SP4
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP5
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP6
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP7
2.7.1-150700.3.12.1
fixed
libexpat1
suse enterprise desktop 15 SP7
2.7.1-150700.3.12.1
fixed
suse enterprise sap 15 SP4
2.7.1-150400.3.37.1
fixed
suse enterprise sap 15 SP5
2.7.1-150400.3.37.1
fixed
suse enterprise sap 15 SP7
2.7.1-150700.3.12.1
fixed
suse enterprise server 12 SP3
2.7.1-21.52.1
fixed
suse enterprise server 12 SP5
2.7.1-21.52.1
fixed
suse enterprise server 15 SP4
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP5
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP6
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP7
2.7.1-150700.3.12.1
fixed
libexpat1-32bit
suse enterprise desktop 15 SP7
2.7.1-150700.3.12.1
fixed
suse enterprise sap 15 SP4
2.7.1-150400.3.37.1
fixed
suse enterprise sap 15 SP5
2.7.1-150400.3.37.1
fixed
suse enterprise sap 15 SP7
2.7.1-150700.3.12.1
fixed
suse enterprise server 12 SP3
2.7.1-21.52.1
fixed
suse enterprise server 12 SP5
2.7.1-21.52.1
fixed
suse enterprise server 15 SP4
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP5
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP6
2.7.1-150400.3.37.1
fixed
suse enterprise server 15 SP7
2.7.1-150700.3.12.1
fixed
libmozjs-115-0
suse enterprise desktop 15 SP7
115.4.0-150600.3.14.1
fixed
suse enterprise sap 15 SP7
115.4.0-150600.3.14.1
fixed
suse enterprise server 15 SP6
115.4.0-150600.3.14.1
fixed
suse enterprise server 15 SP7
115.4.0-150600.3.14.1
fixed
libmozjs-60
suse enterprise desktop 15 SP7
60.9.0-150200.6.11.1
fixed
suse enterprise sap 15 SP4
60.9.0-150200.6.11.1
fixed
suse enterprise sap 15 SP5
60.9.0-150200.6.11.1
fixed
suse enterprise sap 15 SP7
60.9.0-150200.6.11.1
fixed
suse enterprise server 15 SP4
60.9.0-150200.6.11.1
fixed
suse enterprise server 15 SP5
60.9.0-150200.6.11.1
fixed
suse enterprise server 15 SP6
60.9.0-150200.6.11.1
fixed
suse enterprise server 15 SP7
60.9.0-150200.6.11.1
fixed
libmozjs-78-0
suse enterprise sap 15 SP4
78.15.0-150400.3.17.1
fixed
suse enterprise sap 15 SP5
78.15.0-150400.3.17.1
fixed
suse enterprise server 15 SP4
78.15.0-150400.3.17.1
fixed
suse enterprise server 15 SP5
78.15.0-150400.3.17.1
fixed
mozjs115-devel
suse enterprise desktop 15 SP7
115.4.0-150600.3.14.1
fixed
suse enterprise sap 15 SP7
115.4.0-150600.3.14.1
fixed
suse enterprise server 15 SP6
115.4.0-150600.3.14.1
fixed
suse enterprise server 15 SP7
115.4.0-150600.3.14.1
fixed
mozjs60-devel
suse enterprise desktop 15 SP7
60.9.0-150200.6.11.1
fixed
suse enterprise sap 15 SP4
60.9.0-150200.6.11.1
fixed
suse enterprise sap 15 SP5
60.9.0-150200.6.11.1
fixed
suse enterprise sap 15 SP7
60.9.0-150200.6.11.1
fixed
suse enterprise server 15 SP4
60.9.0-150200.6.11.1
fixed
suse enterprise server 15 SP5
60.9.0-150200.6.11.1
fixed
suse enterprise server 15 SP6
60.9.0-150200.6.11.1
fixed
suse enterprise server 15 SP7
60.9.0-150200.6.11.1
fixed
mozjs78-devel
suse enterprise sap 15 SP4
78.15.0-150400.3.17.1
fixed
suse enterprise sap 15 SP5
78.15.0-150400.3.17.1
fixed
suse enterprise server 15 SP4
78.15.0-150400.3.17.1
fixed
suse enterprise server 15 SP5
78.15.0-150400.3.17.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
firefox
Amazon Linux 2023
0:140.8.0-1.amzn2023.0.2
fixed
firefox-debuginfo
Amazon Linux 2023
0:140.8.0-1.amzn2023.0.2
fixed
firefox-debugsource
Amazon Linux 2023
0:140.8.0-1.amzn2023.0.2
fixed
thunderbird
Amazon Linux 2
0:140.8.0-1.amzn2.0.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
expat
Azure Linux 3.0
0:2.6.4-5.azl3
fixed