CVE-2025-59375Disclosure(libexpat_project / libexpat)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch libexpat_project libexpat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libexpat

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-11); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
libexpat

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-12: 1Mentions · 2026-06-21: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 1Technical Details · 2026-06-21: 102-1102-1206-21
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-121
Patch1
2026-06-211
Disclosure1
Full discourse4 posts
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers exploiting libexpat vulnerabilities (CVE-2024-8176, CVE-2025-59375) in Hitachi Energy REB500 systems through crafted IEC 61850 messages. Memory exhaustion and stack overflow attacks target critical energy infrastructure. #CloudSecurity :link: Full breakdown: https://aviatrix.ai/threat-research-center/hitachi-energy-reb500-libexpat-vulnerabilities-cve-2024-8176-cve-2025-59375

    0000040
    2.0K followersView on X
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2025-59375: Denial of Service in Hitachi Energy ITT600 SA Explorer Testing Tool https://breachspider.com/intel/2026-06-21-cve-2025-59375-denial-of-service-in-hitachi-energy-itt600-sa #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The snippet announces the discovery of a denial‑of‑service flaw in Hitachi Energy's ITT600 SA Explorer Testing Tool, identifying CVE‑2025‑59375 but providing no PoC, exploit, patch, or exploitation evidence.

    0000072
    2.3K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 CISA: Siemens SINEC OS flaws hit industrial networking stacks (patch to v3.3+) CISA’s ICSA-26-043-06 (Feb 12, 2026) warns that Siemens SINEC OS versions before v3.3 are affected by multiple vulnerabilities (incl. CVE-2025-39865 and CVE-2025-59375) that could be abused to disrupt or compromise industrial network management components—especially where SINEC OS is deployed alongside Siemens OT networking hardware (e.g., SCALANCE). Update to Siemens’ fixed SINEC OS releases and restrict exposure of management interfaces. 🎯 Target: Global/Industrial (OT Networking) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06

    Post summary

    CISA’s advisory warns that Siemens SINEC OS versions before v3.3 are vulnerable to CVE‑2025‑39865 and CVE‑2025‑59375, and urges users to upgrade to patched releases and limit management interface exposure.

    0000069
    191 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    Expat XML parser flaws in Ubuntu 25.10, 22.04 LTS and older allow DoS or possible code execution via crafted XML, impacting xmltok (CVE-2025-59375, CVE-2026-24515, CVE-2026-25210). #Linux https://threatcluster.io/cluster/critical-expat-vulnerabilities-affect-multiple-ubuntu-releas-7b8a8fa0

    Post summary

    Ubuntu users face Expat XML parser vulnerabilities (CVE‑2025‑59375, CVE‑2026‑24515, CVE‑2026‑25210) that can cause DoS or potential code execution through crafted XML.

    0000058
    79 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibexpat_projectlibexpat---

Explore more