Vulnerability CVE-2024-28757


Published: 2024-03-10

Description:
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

 References:
https://github.com/libexpat/libexpat/pull/842
https://github.com/libexpat/libexpat/issues/839

Copyright 2026, cxsecurity.com

 

Back to Top