libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. [https://nvd.nist.gov/vuln/detail/CVE-2025-59375]