CVE-2025-66382: In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

Overview

Severity
Low (CVSS 2.9)
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U
Exploit Status
Not Exploited
Patch Tuesday
2025-Nov
Released
2025-11-29
Last Updated
2026-03-03
EPSS Score
0.01% (percentile: 1.3%)

Affected Products (5)

Other

  • 20572-17084
  • 20923-17086
  • 20943-17086
  • 20543-17086
  • 20922-17084

Revision History

  • 2025-11-29: Information published.
  • 2025-12-02: Information published.
  • 2025-12-21: Information published.
  • 2025-12-23: Information published.
  • 2026-02-21: Information published.
  • 2026-03-03: Information published.