This is James Clark's expat XML parser library in C. It is a stream oriented
2026-10-05 20:38:06 by Thomas Klausner | Files touched by this commit (2) |  |
Log message:
expat: update to 2.9.0.
Release 2.9.0 Mon October 5 2026
Security fixes:
#1392 CVE-2026-102633 -- Integer overflow in function
expat_realloc on 32bit platforms
#1393 CVE-2026-77214 -- Validate parameter `len` against available
buffer capacity in XML_ParseBuffer
Bug fixes:
#1387 lib: Handle OOM when copying encodingName in XML_ParserReset
New features:
#1327 lib: Introduce new "Properties API" to get and set
scalar properties for a single parser instance.
There are six new functions:
- XML_GetPropertyBool
- XML_GetPropertyDouble
- XML_GetPropertyUInt64
- XML_SetPropertyBool
- XML_SetPropertyDouble
- XML_SetPropertyUInt64
And two new enums:
- XML_Prop_Error
- XML_Parser_Property
#1323 lib: Introduce five new 64bit location API functions:
- XML_GetCurrentByteCount64
- XML_GetCurrentByteIndex64
- XML_GetCurrentColumnNumber64
- XML_GetCurrentLineNumber64
- XML_GetInputContext64
These five functions closely mirror their predecessors
but are not prone to 32bit integer wrap-around.
Other changes:
#1391 docs: Document the scope of function XML_GetErrorCode
#1395 docs: Document length expectations for XML_ParseBuffer
#1394 lib: Call unknown encoding release before parser teardown
#1370 #1373 lib: Drop (disabled-by-default) attribute info feature
These things are now gone:
- Public function XML_GetAttributeInfo
- Public struct XML_AttrInfo
- Macro XML_ATTR_INFO
These things are now causing build errors:
- Configure option --enable-xml-attr-info
- CMake option -DEXPAT_ATTR_INFO=ON
#1379 #1382 lib: Drop (disabled-by-default) minimum size feature
These things are now gone:
- Macro XML_MIN_SIZE
These things are now causing build errors:
- Configuring with -DXML_MIN_SIZE for CPPFLAGS/CFLAGS
- CMake option -DEXPAT_MIN_SIZE=ON
#1323 #1411 lib: Deprecate macro XML_LARGE_SIZE (use the new 64bit
location API functions instead please)
#1323 lib: Deprecate five location API functions that are cursed
with integer wrap-around:
- XML_GetCurrentByteCount
- XML_GetCurrentByteIndex
- XML_GetCurrentColumnNumber
- XML_GetCurrentLineNumber
- XML_GetInputContext
#1399 lib: Guard against out-of-handler use of XML_DefaultCurrent
#1400 lib: Use size_t for bytesAllocated and peakBytesAllocated
#1401 #1402 ..
#1404 #1405 lib|xmlwf|tests: Unify use of xcslen, xcscmp and xcsncmp
#1406 xmlwf: Add missing `#include "expat.h"`
#1389 #1396 Version info bumped from 13:5:12 (libexpat*.so.1.12.5)
to 14:0:13 (libexpat*.so.1.13.0); see https://verbump.de/
for what these numbers do
|
2026-09-23 07:31:06 by Adam Ciarcinski | Files touched by this commit (3) |  |
Log message:
expat: updated to 2.8.5
Release 2.8.5 Tue September 22 2026
Security fixes:
CVE-2026-93990 -- Reject high surrogates not followed by a
low surrogate during UTF-16 decoding; previously, malformed
UTF-16 could be smuggled into the application using Expat
and could cause arbitrary damage there, depending on how
malformed UTF-16 was handled inside the application;
validation was not their job but Expat's. This is similar
to past vulnerability CVE-2022-25235.
Upstream CVSS 3.1 vector:
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVSS score: 9.8)
Bug fixes:
lib: Fix OOM-related memory leak on a failed overflow check
lib: Fix memory alignment for architectures with 128bit
pointers like CHERI-RISC-V
xmlwf: Handle errors when closing output files
Other changes:
lib: Reject an XML declaration version other than `1.[0-9]+`
(which is less strict than XML 1.0r4 (fourth edition)
and matches XML 1.0r5 (fifth edition))
lib: Make Clang, GCC and MSVC warn about use of function
XML_SetHashSalt that is deprecated since Expat 2.8.0
lib: Drop internal macros FASTCALL, PTRCALL, PTRFASTCALL
xmlwf: Document that with `-k` the last error determines the
xmlwf exit code in `--help` output
xmlwf: Make exit code 3 documentation match exit code 2 more
closely in `--help` output
CMake|Windows: Refrain from adding `/source-charset:utf-8`
for MSVC
Autotools: Be explicit about the minimum required version of
GNU Automake, currently version 1.13 of 2012-12-28
Autotools|macOS: Sync CMake templates with CMake 4.4.3
Replace some internal use of XML_Bool with standard bool
tests: Propagate xmltest.sh failures via exit status
tests|xmlwf: Add `include "expat_config.h"` where missing
tests: Start covering hash table operation
tests: Drop __cplusplus leftovers
tests: Fix tail pointer when unlinking the last tracked
allocation
docs: Emphasize that XML_StopParser is not immediate
docs: Sync XML_FeatureEnum value list in doc/reference.html
Version info bumped from 13:4:12 (libexpat*.so.1.12.4)
to 13:5:12 (libexpat*.so.1.12.5); see https://verbump.de/
for what these numbers do
Infrastructure:
Add missing .gitignore entries
CI: Detect missing `include "expat_config.h"`
CI: Bump MinGW Clang from 23.0.1 to 23.1.1
CI: Bump Fil-C from 0.684 to 0.685
CI: Bump Cppcheck from 2.21.0 to 2.22.0
CI: Extract helper script `apply-htmltidy.sh`
Autotools: Start to also produce .tar.bz3 release tarballs
|
2026-08-31 20:16:39 by Thomas Klausner | Files touched by this commit (2) |  |
Log message:
expat: update to 2.8.4.
Release 2.8.4 Mon August 31 2026
Security fixes:
#1321 #1331 CVE-2026-66046, CVE-2026-76641 -- Fix quadratic runtime from
"attribute isCdata lookups" that allowed denial of \
service
attacks through moderately sized crafted XML input
(CWE-407).
The vulnerability is closely related to past CVE-2026-45186
that was fixed with Expat 2.8.1.
Please note that a layer of compression around XML can
significantly reduce the minimum attack payload size.
Upstream CVSS 3.1 vector:
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (CVSS score: 7.5)
(Note the "AV:N" for network/remote.)
#1322 CVE-2026-76957 -- Protect custom encoding callbacks from
parser re-entry. The vulnerability is closely related to
past issues CVE-2026-50219, CVE-2026-56131 and
CVE-2026-56412 that were all fixed with Expat 2.8.2.
#1326 CVE-2026-76956 -- Fix inverted getentropy() return handling
Allows for hash flooding denial of services in
configurations where getentropy is configured or detected
as the only high quality entropy extractor.
Upstream CVSS 3.1 vector:
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H (CVSS score: 5.9)
(Note the "AV:N" for network/remote.)
Other changes:
#1332 #1333 CMake: Only add `/source-charset:utf-8` when `/utf-8` is not
present
#1315 lib: Resolve (currently unreachable) undefined behavior from
overshifting a signed int to the left
#1325 #1334 lib: Support read-only hash table lookup with keys that are
not zero-terminated
#1340 lib: Use a C99 bool for `ENTITY.open`
#1319 Fix typo in comment
#1320 Sync file headers
#1328 #1329 Version info bumped from 13:3:12 (libexpat*.so.1.12.3)
to 13:4:12 (libexpat*.so.1.12.4); see https://verbump.de/
for what these numbers do
Infrastructure:
#1317 #1335 CI: Cover compilation and execution with Fil-C
#1337 CI: Cover compilation and execution on riscv64
#1338 CI: Cover compilation and execution with Clang-based MinGW
#1339 CI: Cover compilation and execution on (big-endian) s390x
#1316 CI: Run test suite with musl, also
#1336 CI: Bump WASI SDK from 33 to 34
#1345 CI: Bump Clang from 22 to 23
Special thanks to:
Alberto Maschietto
Alexander Bluhm
Berkay Eren Ürün
Darren Carreras
Fabian Wahle (Hap Security)
Matteo Forzan
Matthew Fernandez
Sorrashut Kaewtaworn
Wade Sparks III
Zeyou Liu
and
City of Munich Open Source Sabbatical
Moonshot AI
VulnCheck
Z.ai
|
2026-08-11 18:18:02 by Thomas Klausner | Files touched by this commit (3) |  |
Log message:
expat: update to 2.8.3.
Release 2.8.3 Mon August 10 2026
Security fixes:
#1296 CVE-2026-72522 -- Fix an out-of-bounds read and the resulting
infinite loop caused by treating low surrogates (Unicode)
the same as high surrogates in functions *_toUtf16.
Needs Expat compiled with 16bit character support
(e.g. with Firefox and/or on Windows) to be affected.
Upstream CVSS 3.1 vector:
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (CVSS score: 7.5)
(Note the "AV:N" for network/remote, the \
"AV:L" in NVD by
Mitre is mistaken.)
Original bug report from Mozilla at:
https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
Bug fixes:
#1297 #1300 lib: Fix support for 2+ GiB documents (regression from 2.8.2)
#1286 lib: Reject empty version in the XML declaration
#1305 #1306 lib: Fix printf format for AIX
Other changes:
#1309 CMake|AIX: Enable EXPAT_DEV_URANDOM by default for AIX
#1295 CMake|Windows: Add a 64bit MinGW toolchain file
#1287 #1289 CMake|Windows: Start invoking MSVC with /source-charset:utf-8
#1289 CMake|Windows: Start requiring MSVC 2015 Update 2 or later
#1300 Document the current wrap-around issues with functions
- XML_GetCurrentByteIndex
- XML_GetCurrentColumnNumber
- XML_GetCurrentLineNumber
- XML_GetAttributeInfo
explicitly.
#1303 Address Clang Static Analyzer 22 warning
`core.NullPointerArithm`
#1313 #1314 Version info bumped from 13:2:12 (libexpat*.so.1.12.2)
to 13:3:12 (libexpat*.so.1.12.3); see https://verbump.de/
for what these numbers do
Infrastructure:
#1311 CI: Limit workflow runtime and package installation runtime
#1310 CI: Pin Cppcheck version for a robust CI
#1310 CI: Migrate Cppcheck CI from macOS to Linux
#1312 CI: Get CFLAGS and CXXFLAGS back in sync for both Emscripten
and WASI SDK
#1304 CI: Activate AddressSanitizer for MSVC Windows CI
#1308 CI: Introduce zizmor static analysis for GitHub Actions
#1308 CI: Start using `persist-credentials: false` with Git checkout
#1219 CI: Add a 7 day cooldown to Dependabot for GitHub Actions
#1302 #1303 CI: Bump Clang from 21 to 22
#1293 #1294 Update project status for 2026-08
#1301 #1307 Add SPDX license identifiers to the source code
Fix some pkglint while here.
|
2026-06-25 22:59:15 by Thomas Klausner | Files touched by this commit (2) |  |
Log message:
expat: update to 2.8.2.
Release 2.8.2 Thu June 25 2026
Security fixes:
#1246 CVE-2026-50219 -- Disallow calls to functions
`XML_GetBuffer`, `XML_Parse`, `XML_ParseBuffer`,
`XML_ParserFree`, `XML_ParserReset` to guard e.g.
Expat bindings from memory corruption;
this CPython issue is related:
https://github.com/python/cpython/issues/146169
#1267 CVE-2026-56131 -- Protect XML_ResumeParser from being called
from a handler, plugging a hole in the fix
to CVE-2026-50219
#1272 CVE-2026-56132 -- Fix out-of-bound scaffolding index store
in `doProlog`
#1229 #1232 CVE-2026-56403 -- Integer overflow in `storeAtts`
#1249 CVE-2026-56404 -- Integer overflow in `addBinding`
#1251 CVE-2026-56405 -- Integer overflow in `getAttributeId`
#1255 CVE-2026-56406 -- Integer overflow in `XML_ParseBuffer`
#1262 CVE-2026-56407 -- Integer overflow in `textLen` handling
#565 CVE-2026-56408 -- Integer overflow in `copyString`
(commit 16e2efd867ea8567ffa012210b52ef5918e20817)
#1259 CVE-2026-56409 -- xmlwf: Integer overflow in output path join
#1252 CVE-2026-56410 -- xmlwf: Integer overflow in
`resolveSystemId`
#1263 CVE-2026-56411 -- xmlwf: Integer overflow in notation list
allocation
#1278 CVE-2026-56412 -- Guard XML_TOK_DATA_CHARS handler calls in
`doCdataSection`, plugging a hole in the fix to
CVE-2026-50219
Bug fixes:
#1260 xmlwf: Escape names and base URI in meta output
#1266 xmlwf: Pick a safe quote for notation system and public IDs
Other changes:
#1257 CMake|Autotools: Stop using /dev/urandom by default
#1244 #1254 CMake: Fix guard for Unix sources of entropy
#1183 #1270 CMake|Windows: Add missing export for symbol
`XML_SetHashSalt16Bytes`
#1236 CMake: Mark option EXPAT_OSSFUZZ_BUILD as advanced
#1283 Limit output indentation for EXPAT_ENTITY_DEBUG=1 and
allow unlimited indentation via EXPAT_ENTITY_DEBUG=2
#565 Replace some loops by use of `memcpy`, `strlen`, `wcslen`
#1220 lib: Use a size_t for group sizes
#1221 lib: Fix too-conservative integer overflow check when
appending raw name
#1222 lib: Simplify attribute allocation/management logic
#1224 Update fallthrough annotations to satisfy Clang and GCC
#1226 lib: Remove unnecessary void * casts in random code
#1228 lib: Reduce scope of locals in storeAtts
#1230 lib: Count attributes with size_t variables
#1238 Minor get-buffer improvements
#1239 #1240 lib|tests: Include header expat_config.h first
#1241 lib: Shrink size of XML_GetBuffer
#1242 lib: Remove a legacy comment
#1243 lib: XML_ParserReset: Extract repeated linked-list move logic
#1243 lib: Unify entity free lists
#1247 lib: Fix use of '0' as boolean literal
#1248 lib: Make XML_Index overflow check more intuitive
#1256 lib: Use size_t for counting string/URI lengths
#1258 lib: XML_GetInputContext: Remove use of 0 for NULL
#1261 Comment typo fixes
#1275 Teach Memory Sanitizer semantics of randomization functions
#1276 #1281 Version info bumped from 13:1:12 (libexpat*.so.1.12.1)
to 13:2:12 (libexpat*.so.1.12.2); see https://verbump.de/
for what these numbers do
Infrastructure:
#1231 perl-integration.yml: Bump to XML::Parser 2.59
#1237 emscripten.yml: Bump from Ubuntu 22.04 to 24.04
#1183 #1271 windows-build.yml: Cover completeness of file
libexpat.def.cmake
#1274 linux.yml: Make llvm-symbolizer available in CI
Special thanks to:
Alessandro Gario
Asher Darden
Christoph Reiter
Haris Hussain
Matthew Fernandez
Kartik Kenchi
Nick Begg
Sajin S
Yousef Shanableh
and
Anthropic
Astra Security
Trail of Bits
|
2026-05-11 17:51:26 by Adam Ciarcinski | Files touched by this commit (2) |  |
Log message:
expat: updated to 2.8.1
Release 2.8.1 Sun May 10 2026
Security fixes:
CVE-2026-45186 -- Fix quadratic runtime from attribute name
collision checks that allowed denial of service attacks
through moderately sized crafted XML input (CWE-407).
Please note that a layer of compression around XML can
significantly reduce the minimum attack payload size.
Other changes:
Drop more casts related to `void *` that C99 does not need
xmlwf: Streamline use of `mmap`
Version info bumped from 13:0:12 (libexpat*.so.1.12.0)
to 13:1:12 (libexpat*.so.1.12.1); see https://verbump.de/
for what these numbers do
|
| 2026-04-26 21:45:59 by Thomas Klausner | Files touched by this commit (2) |
Log message:
Release 2.8.0 Fri April 24 2026
Security fixes:
#47 #1183 CVE-2026-41080 -- The existing hash flooding protection
(based on SipHash) only used 4 to 8 bytes of entropy for
a salt, when 16 bytes of salt are supported by the
implementation of SipHash used by Expat. Now full 16 bytes
of entropy are used to improve protection against hash
flooding attacks.
Existing API function XML_SetHashSalt is now deprecated
because of its limitations, and its use should be
considered a vulnerability. Please either use the new API
function XML_SetHashSalt16Bytes (with known-high-quality
entropy input only!) instead, or leave the derivation of
a 16-bytes hash salt from high quality entropy to Expat's
internal machinery (by *not* calling either of the two
XML_SetHashSalt* functions).
Bug fixes:
#1188 Avoid propagating /dev/urandom file descriptor to child
processes
#1193 Fix interpretation of `errno` after randomization calls
#1195 Avoid assuming uint8_t is a character type
Other changes:
#1180 #1199 Add support for `getentropy(3)` as a source of entropy;
this helps with protecting against hash flooding attacks,
in particular with WASI SDK (where none of the other
entropy sources supported by libexpat are available).
#1200 Autotools: Add `--without-arc4random` and
`--without-arc4random-buf`
#1200 Autotools: Make `./configure` output report on available
high quality entropy sources
#1173 Autotools|macOS: Sync CMake templates with CMake 4.3.0
#1201 Autotools|CMake: Improve checks for `arc4random` and
`arc4random_buf` e.g. with modern glibc
#1201 CMake: Report on availability of functions `arc4random` and
`arc4random_buf`
#1201 CMake: Mark entropy related build switches as advanced
#1189 ..
#1203 #1204 Extract new files from entropy extraction code
#1194 Stop duplicating C tests 1:1 as C++ ("runtests_cxx")
#1202 Fix a comment typo in expat_external.h
#1187 Fix grammar in compile error message
#1192 examples: Build warning-free with -Wwrite-strings
#1171 tests: Address harmless warning from Coverity
#1170 #1176 Sync file headers
#1190 #1206 Version info bumped from 12:3:11 (libexpat*.so.1.11.3)
to 13:0:12 (libexpat*.so.1.12.0); see https://verbump.de/
for what these numbers do
Infrastructure:
#1166 #1167 ..
#1172 #1175 ..
#1178 #1179 ..
#1185 #1205 CI: Make Perl XML::Parser integration tests run against
both version 2.47 and the latest release 2.58
#1169 CI: Adapt to breaking changes regarding Inno Setup
#1173 CI: Adapt to breaking changes regarding CMake
#1174 CI: Include public corpus of fuzzer `xml_lpm_fuzzer` with
regression testing
#1181 #1182 CI: Bump WASI SDK from 30 to 32
Special thanks to:
Jérôme Duval
Matthew Fernandez
|
2026-03-17 22:20:10 by Thomas Klausner | Files touched by this commit (2) |  |
Log message:
expat: update to 2.7.5.
Ok maya@
Release 2.7.5 Tue March 17 2026
Security fixes:
#1158 CVE-2026-32776 -- Fix NULL function pointer dereference for
empty external parameter entities; it takes use of both
functions XML_ExternalEntityParserCreate and
XML_SetParamEntityParsing for an application to be
vulnerable.
#1161 #1162 CVE-2026-32777 -- Protect from XML_TOK_INSTANCE_START
infinite loop in function entityValueProcessor; it takes
use of both functions XML_ExternalEntityParserCreate and
XML_SetParamEntityParsing for an application to be
vulnerable.
#1163 CVE-2026-32778 -- Fix NULL dereference in function setContext
on retry after an earlier ouf-of-memory condition; it takes
use of function XML_ParserCreateNS or XML_ParserCreate_MM
for an application to be vulnerable.
#1160 Three more unfixed vulnerabilities left
Other changes:
#1146 #1147 Autotools: Fix condition for symbol versioning check, in
particular when compiling with slibtool (not libtool)
#1156 Address Cppcheck >=2.20.0 warnings
#1153 tests: Make test_buffer_can_grow_to_max work for MinGW on
Ubuntu 24.04
#1157 #1159 Version info bumped from 12:2:11 (libexpat*.so.1.11.2)
to 12:3:11 (libexpat*.so.1.11.3); see https://verbump.de/
for what these numbers do
Infrastructure:
#1148 CI: Fix FreeBSD and Solaris CI
#1149 CI: Bump to WASI SDK 30
#1153 CI: Adapt to breaking changes with Ubuntu 22.04
#1156 CI: Adapt to breaking changes in Cppcheck
Special thanks to:
Berkay Eren Ürün
Christian Ng
Fabio Scaccabarozzi
Francesco Bertolaccini
Mark Brand
Rhodri James
and
AddressSanitizer
Buttercup
OSS-Fuzz / ClusterFuzz
Trail of Bits
|