CyberRota Analysis
AI-GeneratedExpat versions up to 2.8.4 are vulnerable to XML injection due to improper validation of UTF-16 encoded input, specifically allowing low surrogates to follow high surrogates. This flaw can be exploited by attackers to craft malicious XML that conceals markup characters, potentially leading to unauthorized data manipulation or execution of arbitrary code. Organizations utilizing Expat for XML parsing should prioritize patching this vulnerability to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.