Vulnerability record

CVE-2025-59375

Severity: HighExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2025-59375 scored CVSS 7.5

    Basis: NIST National Vulnerability Database

  2. Disclosed

    Hitachi Energy REB500

    Basis: CISA Cybersecurity Advisories (government advisory)

Coverage

Severity: HighAction: Mitigate

Hitachi Energy REB500

Mitigate

No complete fix is indicated yet.

References