CVE-2025-59375
Vulnerability Summary
Timeline
Description
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:H/RL:T/RC:C
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Trends
Current EPSS score: 1.31%• Percentile: 69%
Techniques & Countermeasures
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- alpine•expat
< 2.7.2-r0 | < 2.7.2-r0 | < 2.7.2-r0 | < 2.7.2-r0 | < 2.7.2-r0 | < 2.7.2-r0
- chainguard•expat
< 2.7.2-r0
- wolfi•expat
< 2.7.2-r0
- debian•expat
all | all | < 2.8.2-1~deb13u1 | < 2.7.2-1
- debian•firefox-esr
< 140.9.0esr-1~deb11u1 | < 140.9.0esr-1~deb12u1 | < 140.9.0esr-1~deb13u1 | < 140.9.0esr-1
- debian•thunderbird
< 1:140.9.0esr-1~deb11u1 | < 1:140.9.0esr-1~deb12u1 | < 1:140.9.0esr-1~deb13u1 | < 1:140.9.0esr-1
- libexpat_project•libexpat
< 2.7.2
- redhat•expat
< 0:2.7.1-1.el10_0.3 | < 0:2.7.1-1.el10_1.3 | < 0:2.5.0-5.el9_6.1 | < 0:2.5.0-5.el9_7.1 | < 0:2.7.5-1.hum1
- redhat•expat-debuginfo
< 0:2.7.1-1.el10_0.3 | < 0:2.7.1-1.el10_1.3 | < 0:2.5.0-5.el9_6.1 | < 0:2.5.0-5.el9_6.1 | < 0:2.5.0-5.el9_7.1 | < 0:2.5.0-5.el9_7.1
- redhat•expat-debugsource
< 0:2.7.1-1.el10_0.3 | < 0:2.7.1-1.el10_1.3 | < 0:2.5.0-5.el9_6.1 | < 0:2.5.0-5.el9_6.1 | < 0:2.5.0-5.el9_7.1 | < 0:2.5.0-5.el9_7.1
- redhat•expat-devel
< 0:2.7.1-1.el10_0.3 | < 0:2.7.1-1.el10_1.3 | < 0:2.5.0-5.el9_6.1 | < 0:2.5.0-5.el9_7.1
- redhat•mingw-expat
< 0:2.5.0-1.el8_10
- redhat•mingw-fontconfig
< 0:2.12.6-4.el8_10
- redhat•mingw32-expat
< 0:2.5.0-1.el8_10
- redhat•mingw32-expat-debuginfo
< 0:2.5.0-1.el8_10
- redhat•mingw32-fontconfig
< 0:2.12.6-4.el8_10
- redhat•mingw32-fontconfig-debuginfo
< 0:2.12.6-4.el8_10
- redhat•mingw64-expat
< 0:2.5.0-1.el8_10
- redhat•mingw64-expat-debuginfo
< 0:2.5.0-1.el8_10
- redhat•mingw64-fontconfig
< 0:2.12.6-4.el8_10
- redhat•mingw64-fontconfig-debuginfo
< 0:2.12.6-4.el8_10
References (34)
- https://github.com/libexpat/libexpat/issues/1018
- https://github.com/libexpat/libexpat/pull/1034
- https://github.com/libexpat/libexpat/blob/676a4c531ec768732fac215da9730b5f50fbd2bf/expat/Changes#L45-L74
- https://issues.oss-fuzz.com/issues/439133977
- https://github.com/libexpat/libexpat/blob/R_2_7_2/expat/Changes
- http://www.openwall.com/lists/oss-security/2025/09/16/2
- http://www.openwall.com/lists/oss-security/2026/05/01/5
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://cert-portal.siemens.com/productcert/html/ssa-089022.html
- https://access.redhat.com/errata/RHSA-2025:19403
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2395108
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_19403.json
- https://access.redhat.com/security/cve/CVE-2025-59375
- https://www.cve.org/CVERecord?id=CVE-2025-59375
- https://nvd.nist.gov/vuln/detail/CVE-2025-59375
- https://www.mozilla.org/security/advisories/mfsa2026-22/#CVE-2025-59375
- https://www.mozilla.org/security/advisories/mfsa2026-24/#CVE-2025-59375
- https://access.redhat.com/errata/RHSA-2025:21030
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_21030.json
- https://access.redhat.com/errata/RHSA-2025:21773
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_21773.json
- https://access.redhat.com/errata/RHSA-2025:21974
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_21974.json
- https://access.redhat.com/errata/RHSA-2025:22175
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22175.json
- https://access.redhat.com/errata/RHSA-2026:3407
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3407.json
- https://access.redhat.com/errata/RHSA-2026:5396
- https://access.redhat.com/security/updates/classification/
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5396.json
- https://security-tracker.debian.org/tracker/CVE-2025-59375
- https://security.alpinelinux.org/vuln/CVE-2025-59375
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59375.json