Expat 1,381 (github.com/libexpat/libexpat (https://github.com/libexpat/libexpat 1,381 ), MIT; 2.8.5 released 22 September 2026, Ubuntu 225 ships 2.7.4) is a small, non-validating, SAX-style C parser that James Clark started in 1998. It is inside Python (xml.parsers.expat, ElementTree), Apache httpd and Firefox 555 , and it is incremental: you feed it bytes as they arrive. Run python3 expat_sum.py booknest-catalog.xml:
import sys
from xml.parsers import expat # Python's thin binding to libexpat
state = {"in_price": False, "total": 0.0}
p = expat.ParserCreate()
p.buffer_text = True # join text split across buffers
p.StartElementHandler = lambda name, attrs: state.update(in_price=name == "price")
p.EndElementHandler = lambda name: state.update(in_price=False)
p.CharacterDataHandler = lambda data: state["in_price"] and state.update(
total=state["total"] + float(data))
with open(sys.argv[1], "rb") as f:
while chunk := f.read(65536): # feed it in 64 KiB pieces
p.Parse(chunk, False)
p.Parse(b"", True)
print(f"{expat.EXPAT_VERSION}: total {state['total']:.2f}")Output
expat_2.7.4: total 134.74
Expat checks well-formedness only (a mismatched tag raises ExpatError: mismatched tag); keep it updated, as it parses untrusted input almost everywhere.
Expat
Expat 1,381 is a parser library written in C. It is stream-oriented, open-source, and used in the Apache HTTP Server, Mozilla, Perl, Python, and PHP, among many other languages and applications.Expat is a non-validating, event-driven parser in the style of SAX: it reports parsing events, such as element starts and ends and character data, to application-registered callback (handler) functions as it streams through the document, without checking the document against a DTD or other schema beyond well-formedness. Originally written by James Clark, it is maintained today as libexpat and distributed under the MIT license.
Because it is a small, portable C library, Expat is commonly embedded in other languages via bindings, such as Python's xml.parsers.expat module and PHP's ext/xml extension, rather than used directly by application code.
| Language | C |
| Processing model | Stream-oriented, event-driven (SAX-style) |
| Validation | Non-validating; checks well-formedness only |
| License | Open source (MIT license) |
| Notable users | Apache HTTP Server, Mozilla, Perl, Python, PHP, and others |
#include <expat.h>
#include <stdio.h>
static void startElement(void *data, const char *name, const char **attr) {
printf("<%s>\n", name);
}
static void endElement(void *data, const char *name) {
printf("</%s>\n", name);
}
int main() {
XML_Parser parser = XML_ParserCreate(NULL);
XML_SetElementHandler(parser, startElement, endElement);
/* XML_Parse(parser, buffer, length, isFinal); */
XML_ParserFree(parser);
return 0;
}