https://github.com/libexpat/libexpat/pull/1321 reports:
Expat through 2.8.3 contains a denial of service vulnerability
caused by quadratic algorithmic complexity in the storeAtts()
function in xmlparse.c, where processing N specified attributes
with non-normalized values triggers an O(N^2) linear scan of
elementType->defaultAtts to determine CDATA status. A remote
unauthenticated attacker can supply a single well-formed XML document
of a few megabytes to an application parsing untrusted XML to cause
excessive CPU consumption, resulting in denial of service without
requiring authentication, external entity resolution, or non-default
parser options.