- Sources: primary, discussion
- Summary: Expat 2.8.3 fixes CVE-2026-72522, which the maintainer describes as technically an out-of-bounds read in UTF-16 decoding whose practical symptom is easy and reliable denial of service through an infinite loop. The maintainer states the flaw needs no local access and that the NVD vector nonetheless records the attack vector as Local. The release also fixes a regression in 2.8.2 that wrongly rejected XML content of 2 GiB or more as out of memory on 32-bit platforms and on 64-bit Windows. The Mozilla Security Team reported the vulnerability.
- Why it matters: Expat is bundled and pinned across a large part of the C and Python stack, so the fix has to travel through many vendored copies, and a severity triage that reads the NVD vector alone will score it too low.
- Follow-up: Whether the NVD vector is corrected, and downstream rebuilds of vendored copies.
send feedback on this story