Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2025-41

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to ...

JLSEC Published
Modified
Affected Packages
Expat_jll < 2.2.10+0
Aliases / Upstream
CVE-2019-15903

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XMLGetCurrentLineNumber (or XMLGetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

References