#VU60733 Input validation error in expat - CVE-2022-25236
Published: February 21, 2022 / Updated: June 17, 2022
expat
libexpat.org
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper protection against insertion of namesep characters into namespace URIs in xmlparse.c. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.