Related Vulnerabilities: CVE-2022-25236  

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

Description

The MITRE CVE dictionary describes this issue as:

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

Additional Information

  • Bugzilla 2056370: CVE-2022-25236 expat: expat allows attackers to insert namespace-separator characters into namespace URIs
  • FAQ: Frequently asked questions about CVE-2022-25236