Impact
Expat, prior to version 2.8.5, does not verify that a high surrogate in UTF‑16 input is followed by a low surrogate, allowing XML documents containing lone high surrogate code units to be parsed successfully. These malformed UTF‑16 sequences are passed through by the library to applications compiled with XML_UNICODE or are silently replaced in other builds, leading to corruption or unexpected alteration of XML content.
Affected Systems
The libexpat XML parsing library, versions up to and including 2.8.4, is affected. Any software that links against these releases—regardless of the operating system—may be vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS of less than 1% indicates a very low but nonzero chance of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The typical attack vector is a remote client that submits a crafted UTF‑16 XML document to a service using libexpat.
OpenCVE Enrichment
Debian DLA