{"id":"CVE-2026-102633","summary":"libexpat 2.7.2 through 2.8.5 Integer Overflow in expat_realloc","details":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.","modified":"2026-09-30T03:47:09.122744156Z","published":"2026-09-29T16:04:16.738Z","database_specific":{"cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102633.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102633.json"},{"type":"PACKAGE","url":"https://github.com/libexpat/libexpat"},{"type":"ARTICLE","url":"https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003"},{"type":"FIX","url":"https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118"},{"type":"FIX","url":"https://github.com/libexpat/libexpat/pull/1392"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libexpat/libexpat","events":[{"introduced":"7643f96bd5b9f5d3b26ea112519e05e17ef91cfb"},{"last_affected":"4b3f0b06f39fb5529cead381694f8929901bc273"}],"database_specific":{"extracted_events":[{"introduced":"2.7.2"},{"last_affected":"2.8.5"}],"source":"AFFECTED_FIELD"}}],"versions":["R_2_8_5","R_2_8_4","R_2_8_3","R_2_8_2","R_2_8_1","R_2_8_0","R_2_7_5","R_2_7_4","R_2_7_3","R_2_7_2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102633.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}