Expat 2.8.4 released, fixes 4 vulnerabilities
For readers new to Expat:
libexpat is a fast streaming XML parser. Alongside libxml2, Expat is one of the most widely used software libre XML parsers written in C, specifically C99. It is cross-platform and licensed under the MIT license.
Expat 2.8.4 was released a few hours ago. The key motivation for cutting a release and doing so now was getting the fixes to four vulnerabilities…
…into the hands of the community.
The vulnerabilities were reported by Darren Carreras, Fabian Wahle (Hap Security), Sorrashut Kaewtaworn, Zeyou Liu, and the fixing was done by Darren Carreras, Sorrashut Kaewtaworn, Zeyou Liu, and me — thank you!
Issue CVE-2026-66046 is worth illustrating, and the fixing pull request contains an attack payload generator in its description. The issue was that if an attacker dials up a document like…
<!DOCTYPE e [ <!ATTLIST e a0 NMTOKEN "x"> <!ATTLIST e a1 NMTOKEN "x"> <!ATTLIST e a2 NMTOKEN "x"> ]> <e a0=" v " a1=" v " a2=" v " />
…from 3 attributes to thousands, they could leverage the now-past
quadratic runtime nature of Expat's related machinery
to cause denial of service
even with moderatly sized payload.
The fix was migrating from an O(n) loop to an
amortized O(1)
hash table lookup.
As usual, there is also non-security work that went into this release. For instance, on the infrastructure side of things, the CI now covers Fil-C, RISC-V, Clang-based MinGW, and (the big-endian architecture) s390x for the first time.
It should be noted that it was the Open Source Sabbatical of the City of Munich that allowed me to focus on libexpat for the community through its funding — thank you! This has been the first month, and there are hopefully five more productive ones to come; there continues to be plenty to do. Wish me luck!
Thanks to everyone who contributed to this release of Expat!
For more details about this release, please check out the change log.
If you maintain Expat packaging, a bundled copy of Expat, or a pinned version of Expat, please update to version 2.8.4. Thank you!
Sebastian Pipping