Germany's dCERT published two advisories covering denial-of-service vulnerabilities in the Expat XML parsing library, including libexpat and expat packages. The notices identify multiple flaws in libexpat and an additional vulnerability in expat that could allow attackers to crash affected applications or otherwise disrupt service availability.
The advisories, tracked as dCERT 2026-0719 and dCERT 2026-1142, indicate that systems using vulnerable Expat components may be exposed where untrusted XML input is processed. Organizations relying on software that embeds Expat should review vendor guidance, identify affected dependencies, and prioritize updates or mitigations to reduce denial-of-service risk.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
dCERT published advisory 2026-1420 describing an expat vulnerability that allows denial of service. This is a new advisory distinct from the previously listed 2026-0719 and 2026-1142 notices.
dCERT published advisory 2026-1142 describing an expat vulnerability that allows denial of service.
dCERT published advisory 2026-0719 covering multiple vulnerabilities in libexpat that could allow denial-of-service conditions.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
dcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.