libexpat
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*
- < 2.8.1
A denial-of-service vulnerability has been identified in libexpat versions prior to 2.8.1. The issue arises from the computational complexity involved in checking for collisions in attribute names, which can be exploited using moderately sized crafted XML input.
Exploitation of this vulnerability leads to the denial-of-service condition, causing the application to become unresponsive or unavailable.
Users can upgrade to libexpat version 2.8.1 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.