Home
Packages
Vulnerabilities
Vendors
Report
Policy
Login
Signup
« List of all CVEs
CVE-2026-32777
Published:
3/16/2026
Last updated:
3/16/2026
Reserved:
3/16/2026
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CNA assigner:
mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca)
Requested by:
n/a
Metrics
Version
Score
Severity
Vector String
3.1
4
Medium
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Opam packages affected (4)
conf-expat
conf-gtk2
conf-gtk3
ocaml-expat
Products affected (1)
Product
Vendor
Version
libexpat
libexpat project
< 10.0.19045.5371
References (4)
https://github.com/libexpat/libexpat/pull/1159
https://github.com/libexpat/libexpat/issues/1161
https://github.com/libexpat/libexpat/pull/1162
https://issues.oss-fuzz.com/issues/486993411