Skip to content

libexpat CVE-2022-25314

Moderate
webern published GHSA-q6jm-mm6c-r7m4 Mar 30, 2022

Package

libexpat (bottlerocket)

Affected versions

<1.7.0

Patched versions

1.7.0

Description

Description

This flaw has been rated as having a severity of Moderate. The encoding name parameter is often hard-coded (rather than user input) and it would take a value in the gigabytes for the name to trigger this issue.

Severity

Moderate

CVE ID

CVE-2022-25314

Weaknesses

No CWEs