Description
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
Published: 2024-03-10
Score: 7.5 High
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-25843 libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
Ubuntu USN Ubuntu USN USN-6694-1 Expat vulnerabilities
History

Tue, 04 Nov 2025 22:30:00 +0000


Tue, 04 Nov 2025 19:30:00 +0000


Fri, 28 Mar 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject fedora
Libexpat Project
Libexpat Project libexpat
Netapp
Netapp active Iq Unified Manager
Netapp h300s
Netapp h300s Firmware
Netapp h410c
Netapp h410c Firmware
Netapp h410s
Netapp h410s Firmware
Netapp h500s
Netapp h500s Firmware
Netapp h610c
Netapp h610c Firmware
Netapp h610s
Netapp h610s Firmware
Netapp h700s
Netapp h700s Firmware
Netapp oncommand Workflow Automation
Netapp ontap
Netapp ontap Tools
Netapp windows Host Utilities
CPEs cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:windows_host_utilities:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject fedora
Libexpat Project
Libexpat Project libexpat
Netapp
Netapp active Iq Unified Manager
Netapp h300s
Netapp h300s Firmware
Netapp h410c
Netapp h410c Firmware
Netapp h410s
Netapp h410s Firmware
Netapp h500s
Netapp h500s Firmware
Netapp h610c
Netapp h610c Firmware
Netapp h610s
Netapp h610s Firmware
Netapp h700s
Netapp h700s Firmware
Netapp oncommand Workflow Automation
Netapp ontap
Netapp ontap Tools
Netapp windows Host Utilities

Subscriptions

Fedoraproject Fedora
Libexpat Project Libexpat
Netapp Active Iq Unified Manager H300s H300s Firmware H410c H410c Firmware H410s H410s Firmware H500s H500s Firmware H610c H610c Firmware H610s H610s Firmware H700s H700s Firmware Oncommand Workflow Automation Ontap Ontap Tools Windows Host Utilities
Redhat Enterprise Linux Rhel Eus
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-04T22:06:07.049Z

Reserved: 2024-03-10T00:00:00.000Z

Link: CVE-2024-28757

cve-icon Vulnrichment

Updated: 2025-11-04T22:06:07.049Z

cve-icon NVD

Status : Modified

Published: 2024-03-10T05:15:06.570

Modified: 2025-11-04T22:15:59.800

Link: CVE-2024-28757

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-03-10T00:00:00Z

Links: CVE-2024-28757 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses