Loading
Generated remediation guidance and an executive summary. No account required.
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
Cite this page
CVE-2012-1148. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2012-1148
Use CWE-399, Libexpat Project vendor hub and Libexpat product page to widen CVE-2012-1148 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-45492, CVE-2024-45491 and CVE-2025-59375 for nearby disclosures in the same product family.