expat: internal entity expansion
Published Jan 21, 2014
6.8
MEDIUMCVSS 2.0
EPSS 19.43%
Description
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE.
Affected products
No data.
Configuration 1
- < 2.4.0
Configuration 2
No data.
Red Hat Enterprise Linux 8
expat-0:2.5.0-1.el8_10
Fixed · RHSA-2025:21776
Red Hat Enterprise Linux 8.2 Advanced Update Support
expat-0:2.2.10-1.el8_2
Fixed · RHSA-2025:22871
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
expat-0:2.2.10-1.el8_4
Fixed · RHSA-2025:22785
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
expat-0:2.2.10-1.el8_4
Fixed · RHSA-2025:22785
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
expat-0:2.2.10-1.el8_6
Fixed · RHSA-2025:22842
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
expat-0:2.2.10-1.el8_6
Fixed · RHSA-2025:22842
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
expat-0:2.2.10-1.el8_6
Fixed · RHSA-2025:22842
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
expat-0:2.2.10-1.el8_8
Fixed · RHSA-2025:22607
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
expat-0:2.2.10-1.el8_8
Fixed · RHSA-2025:22607
Red Hat Enterprise Linux 9
expat-0:2.4.9-1.el9_1
Fixed · RHBA-2022:8290
Red Hat Enterprise Linux 9
expat-0:2.4.9-1.el9_1
Fixed · RHBA-2022:8290
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
expat-0:2.2.10-12.el9_0.4
Fixed · RHSA-2025:22035
Red Hat Enterprise Linux 5
expat
Will not fix
Red Hat Enterprise Linux 6
expat
Will not fix
Red Hat Enterprise Linux 7
expat
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | expat-0:2.5.0-1.el8_10 | Fixed | RHSA-2025:21776 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | expat-0:2.2.10-1.el8_2 | Fixed | RHSA-2025:22871 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | expat-0:2.2.10-1.el8_4 | Fixed | RHSA-2025:22785 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | expat-0:2.2.10-1.el8_4 | Fixed | RHSA-2025:22785 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | expat-0:2.2.10-1.el8_6 | Fixed | RHSA-2025:22842 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | expat-0:2.2.10-1.el8_6 | Fixed | RHSA-2025:22842 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | expat-0:2.2.10-1.el8_6 | Fixed | RHSA-2025:22842 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | expat-0:2.2.10-1.el8_8 | Fixed | RHSA-2025:22607 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | expat-0:2.2.10-1.el8_8 | Fixed | RHSA-2025:22607 |
| Red Hat Enterprise Linux 9 | expat-0:2.4.9-1.el9_1 | Fixed | RHBA-2022:8290 |
| Red Hat Enterprise Linux 9 | expat-0:2.4.9-1.el9_1 | Fixed | RHBA-2022:8290 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | expat-0:2.2.10-12.el9_0.4 | Fixed | RHSA-2025:22035 |
| Red Hat Enterprise Linux 5 | expat | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | expat | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | expat | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 19.43% (0.19433) | 97.29th | v5 (v2026.06.15) |
| Jun 15, 2026 | 19.43% (0.19433) | 97.01th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00067) | 18.06th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.52% (0.00523) | 77.66th | v3 (v2023.03.01) |
| Mar 22, 2024 | 0.52% (0.00523) | 76.42th | v3 (v2023.03.01) |
| Jan 20, 2024 | 0.52% (0.00523) | 74.42th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.54% (0.00543) | 74.46th | v3 (v2023.03.01) |
| Jul 18, 2023 | 0.57% (0.00571) | 74.94th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.56% (0.00555) | 74.12th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.93% (0.03932) | 85.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.93% (0.03932) | 84.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.93% (0.03932) | 67.70th | v2 (v2022.01.01) |
References (29)
- http://openwall.com/lists/oss-security/2013/02/22/3 mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Oct/61 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Oct/62 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Oct/63 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/33 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/34 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/35 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/38 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/39 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/40 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://securitytracker.com/id?1028213 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2013/04/12/6 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/10/07/4 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.osvdb.org/90634 vdb-entryx_refsource_OSVDBBroken Link
- http://www.securityfocus.com/bid/58233 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2013-0340 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1000109 Issue Tracking
- https://github.com/libexpat/libexpat/blob/R_2_4_1/expat/Changes
- https://lists.apache.org/thread.html/r41eca5f4f09e74436cbb05dec450fc2bef37b5d3e966aa7cc5fada6d%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfb2c193360436e230b85547e85a41bea0916916f96c501f5b6fc4702%40%3Cusers.openoffice.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2013-0340
- https://security.gentoo.org/glsa/201701-21 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://support.apple.com/kb/HT212804 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT212805 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT212807 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT212814 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT212815 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT212819 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2013-0340
Change history (0)
No recorded changes yet.