Skip to content

libexpat CVE-2024-28757

Moderate
rpkelly published GHSA-rjp2-2459-62cp Apr 2, 2024

Package

libexpat (bottlerocket)

Affected versions

< 1.19.3

Patched versions

1.19.3

Description

libexpat through 2.6.1 contains an XML Entity Expansion flaw when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

Severity

Moderate

CVE ID

CVE-2024-28757

Weaknesses

No CWEs