Skip to content

Bump libexpat from 2.6.4 to 2.7.3#3458

Merged
mattleibow merged 2 commits intomainfrom
dev/update-expat
Jan 27, 2026
Merged

Bump libexpat from 2.6.4 to 2.7.3#3458
mattleibow merged 2 commits intomainfrom
dev/update-expat

Conversation

@mattleibow
Copy link
Copy Markdown
Contributor

Summary

Update libexpat to 2.7.3 to fix security vulnerabilities.

Security Fixes

  • CVE-2025-59375 (CVSS 7.5 HIGH) - Memory exhaustion DoS via crafted XML
  • CVE-2024-50602 (CVSS 5.9 Medium) - Parser crash via XML_ResumeParser

Changes

  • Updated externals/skia submodule to mono/skia@58763ac5b0
  • Updated cgmanifest.json with new commit hash

Related Issues

@github-actions
Copy link
Copy Markdown

Triage Summary

No labels will be applied as the issue relates to updating an external library for security fixes, which does not fit into any of the specified labels.

This issue is not a regression as it pertains solely to a library update for security reasons and does not involve any previously functioning features.

Additional remarks:

  • No labels are applicable since the issue discusses an update related to security vulnerabilities and external libraries.
  • The issue does not correlate with any specific operating system, platform, or environment that is covered by the available labels.
  • It solely focuses on security aspects and does not impact compatibility, performance, or reliability.
Detailed Summary and Actions

Summary of the triage:

  • The issue is focused on updating a library for security fixes and does not relate to any specific labels.
  • There are no affected platforms or areas that are relevant based on the existing labels.
  • The main concern is the security vulnerabilities and the update of a library version.

Summary of the actions that will be performed:

Action Item Description
No Action - The issue does not correspond with any relevant labels to be applied.

This entire triage process was automated by AI and mistakes may have been made. Please let us know so we can continue to improve.

Fixes CVE-2025-59375 (CVSS 7.5 HIGH) - Memory exhaustion DoS
Fixes CVE-2024-50602 (CVSS 5.9 Medium) - Parser crash
@mattleibow mattleibow merged commit dcd1d3a into main Jan 27, 2026
1 of 2 checks passed
@mattleibow mattleibow deleted the dev/update-expat branch January 27, 2026 22:11
@mattleibow mattleibow added the copilot Created by GitHub Copilot label Feb 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

copilot Created by GitHub Copilot

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

[BUG] Bump libexpat in Skia deps to ≥2.6.4 (CVE-2024-50602) [BUG] Bump libexpat in Skia deps to ≥2.7.2 (CVE-2025-59375)

1 participant