CVE-2025-66382

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/11/2025
Last modified:
19/12/2025

Description

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* 2.7.3 (including)