Skip to main content

Expat 2.9.0 released, fixes two vulnerabilities

For readers new to Expat:

libexpat is a fast streaming XML parser. Alongside libxml2, Expat is one of the most widely used software libre XML parsers written in C, specifically C99. It is cross-platform and licensed under the MIT license.

Expat 2.9.0 was released a few hours ago. The key motivation for cutting a release now was to get the security fixes and also new features into the hands of Expat's users.

The two security issues are:

  • CVE-2026-77214 — a potential out-of-bounds read with function XML_ParseBuffer due to insufficient validation of the length parameter,
  • CVE-2026-102633 — an integer overflow in memory management code that affects 32-bit platforms.

If the link for CVE-2026-77214 still results in 404 NOT FOUND by the time of reading, that's because publishing is still in progress.

For CVE-2026-102633 I would like to thank Filippo Tedeschi and Matthew Fernandez. For CVE-2026-77214 I would like to thank Filippo Tedeschi once more, as well as Fabian Wahle (Hap Security).

One of the two new features is the so-called new "Properties API". You can think of properties as the control knobs of a parser. There are five properties at the moment in Expat 2.9.0…

  • Two for the parameters of the allocation tracker/limiter, which prevents maliciously excessive use of memory:
    • XML_PROP_ALLOC_TRACKER_ACTIVATION_THRESHOLD of type uint64_t
    • XML_PROP_ALLOC_TRACKER_MAXIMUM_AMPLIFICATION of type double
  • Another two for the parameters of the protection against billion laughs attacks:
    • XML_PROP_BILLION_LAUGHS_ACTIVATION_THRESHOLD of type uint64_t
    • XML_PROP_BILLION_LAUGHS_MAXIMUM_AMPLIFICATION of type double
  • One for the state of reparse deferral:
    • XML_PROP_REPARSE_DEFERRAL_ENABLED of type XML_Bool

…and there are getters and setters to adjust or retrieve their values:

The new API was introduced to:

  • allow Expat to add more properties — both security-related and non-security ones — in the future (without need to also add new related getter and setter functions for each of them as was the case in the past),
  • allow users to read (not just to set) the current values, and
  • allow users to distinuish the different sources of error beyond a mere "did not work".

The other feature being introduced with release 2.9.0 is the 64-bit location API. The old location API, that is made up of the five functions…

…has the core problem that it uses datatypes int, XML_Index and XML_Size. These data types are not big enough to work with XML content of more than 4 GiB in size: at some point they would wrap around. Macro XML_LARGE_SIZE that increased the size of these datatypes was introduced with Expat 2.0.0 in 2006 to address that problem, but the macro breaks ABI compatibility with anyone that is expecting the smaller datatypes, splitting the world in two, and is not commonly activated — the sitation was not great.

To improve on that situation, Expat 2.9.0 now deprecates macro XML_LARGE_SIZE and offers five new 64-bit versions in return, note the "64" at the end:

This approach now allows everyone that previously relied on the XML_LARGE_SIZE macro to return to mainstream Expat while having access to 64-bit location information that supports XML content beyond 4 GiB in size without wrapping around.

As usual, there are non-security non-feature improvements included with this release. For more details about this release, please check out the change log.

It should be noted that it was the Open Source Sabbatical of the City of Munich that allowed me to focus on libexpat for this release through its funding — thank you! We're in the third month of hopefully six months total; there continues to be plenty to do. Wish me luck!

If your business relies on Expat beyond January 2027, please consider funding the maintenance of Expat to ensure its health and security for you and others. Thank you!

Thanks to everyone who contributed to this release of Expat!

If you maintain Expat packaging, a bundled copy of Expat, or a pinned version of Expat, please update to version 2.9.0. Thank you!

Sebastian Pipping