Skip to content

libexpat CVE-2022-25313

Moderate
webern published GHSA-x6p7-99mx-mwxq Mar 30, 2022

Package

libexpat (bottlerocket)

Affected versions

<1.7.0

Patched versions

1.7.0

Description

Description

A flaw was found in expat. A stack exhaustion in doctype parsing could be triggered by a file with a large number of opening braces, resulting in a denial of service.

Severity

Moderate

CVE ID

CVE-2022-25313

Weaknesses

No CWEs