CVE-2024-28757
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
- Published
- Mar 10, 2024
- Updated
- Nov 4, 2025
- Assigning CNA
- mitre
- Evidence observed
- Aug 4, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HLow · next 30 days
- Percentile
- 79.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
Sources
2- expat_2_1_0_CVE-2024-28757Research
C library for stream-oriented XML parsing, with a focus on analyzing and reproducing CVE-2024-28757 vulnerability in Expat 2.1.0.
- expat_CVE-2024-28757Research
C library for stream-oriented XML parsing with handler registration, supporting UTF-8/UTF-16 encoding, and autoconf-based build system. Includes xmlwf tool and reference manual.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.