libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
https://www.cisa.gov/news-events/ics-advisories/icsa-26-062-03
https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06