libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
| Vendor | Product | Versions |
|---|---|---|
| libexpat_project | libexpat | 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | expat | cert_advisory | 90% |
Updated severity to LOW and marked the vulnerability as exploit available and actively exploited.
Updated affected versions to include 2.7.5, changed severity to MEDIUM, and noted that no exploit is available.
Initial creation