xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks...
High severity
Unreviewed
Published
Feb 17, 2022
to the GitHub Advisory Database
•
Updated May 5, 2025
Description
Published by the National Vulnerability Database
Feb 16, 2022
Published to the GitHub Advisory Database
Feb 17, 2022
Last updated
May 5, 2025
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
References