-
Notifications
You must be signed in to change notification settings - Fork 97
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CVE-2022-23852] of underlying libexpat #215
Comments
Using an OS with package management, I've always wondered why we vendored libexpat. |
If only all OSes brought libs like that ... but wait - we might even get fewer security fixes for older devices where nobody updates the OS :D |
Please note that Expat 2.4.5 with more security fixes has been released by now. |
Are there any plans to upgrade the bundled libexpat version to latest? |
The underlying version of libexpat packaged in node-expat is most likely vulnerable to the vulnerability documented for libexpat < 2.4.4
The text was updated successfully, but these errors were encountered: