Loading
Generated remediation guidance and an executive summary. No account required.
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
Cite this page
CVE-2024-28757. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-28757
Use CWE-776, Libexpat Project vendor hub and Libexpat product page to widen CVE-2024-28757 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-45492, CVE-2024-45491 and CVE-2025-59375 for nearby disclosures in the same product family.