expat
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 28 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 22, 2013 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →libexpat 2.8.1 fixes CVE-2026-45186 (denial of service)
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
libexpat 2.8.1 fixes CVE-2026-45186 (denial of service)
libexpat 2.8.0 fixes CVE-2026-41080 (insufficient entropy)
libexpat 2.8.0 fixes CVE-2026-41080 (insufficient entropy)
libexpat 2.7.5 fixes the vulnerabilities (2x null def, 1x infinite loop)
expat looking for help with another unfixed non-public denial-of-service vulnerability [CVE-2025-66382]
Monitor expat in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.