Expat

Expat 1,381 (github.com/libexpat/libexpat (https://github.com/libexpat/libexpat 1,381 ), MIT; 2.8.5 released 22 September 2026, Ubuntu 225 ships 2.7.4) is a small, non-validating, SAX-style C parser that James Clark started in 1998. It is inside Python (xml.parsers.expat, ElementTree), Apache httpd and Firefox 555 , and it is incremental: you feed it bytes as they arrive. Run python3 expat_sum.py booknest-catalog.xml:

expat_sum.py: feeding Expat 64 KiB at a timePython
import sys
from xml.parsers import expat                     # Python's thin binding to libexpat
state = {"in_price": False, "total": 0.0}
p = expat.ParserCreate()
p.buffer_text = True                              # join text split across buffers
p.StartElementHandler = lambda name, attrs: state.update(in_price=name == "price")
p.EndElementHandler = lambda name: state.update(in_price=False)
p.CharacterDataHandler = lambda data: state["in_price"] and state.update(
    total=state["total"] + float(data))
with open(sys.argv[1], "rb") as f:
    while chunk := f.read(65536):                 # feed it in 64 KiB pieces
        p.Parse(chunk, False)
p.Parse(b"", True)
print(f"{expat.EXPAT_VERSION}: total {state['total']:.2f}")
Output
expat_2.7.4: total 134.74

Expat checks well-formedness only (a mismatched tag raises ExpatError: mismatched tag); keep it updated, as it parses untrusted input almost everywhere.


Expat

Expat 1,381 is a parser library written in C. It is stream-oriented, open-source, and used in the Apache HTTP Server, Mozilla, Perl, Python, and PHP, among many other languages and applications.

Expat is a non-validating, event-driven parser in the style of SAX: it reports parsing events, such as element starts and ends and character data, to application-registered callback (handler) functions as it streams through the document, without checking the document against a DTD or other schema beyond well-formedness. Originally written by James Clark, it is maintained today as libexpat and distributed under the MIT license.

Because it is a small, portable C library, Expat is commonly embedded in other languages via bindings, such as Python's xml.parsers.expat module and PHP's ext/xml extension, rather than used directly by application code.

LanguageC
Processing modelStream-oriented, event-driven (SAX-style)
ValidationNon-validating; checks well-formedness only
LicenseOpen source (MIT license)
Notable usersApache HTTP Server, Mozilla, Perl, Python, PHP, and others
ch09-expat-callback.c
#include <expat.h>
#include <stdio.h>

static void startElement(void *data, const char *name, const char **attr) {
    printf("<%s>\n", name);
}

static void endElement(void *data, const char *name) {
    printf("</%s>\n", name);
}

int main() {
    XML_Parser parser = XML_ParserCreate(NULL);
    XML_SetElementHandler(parser, startElement, endElement);

    /* XML_Parse(parser, buffer, length, isFinal); */

    XML_ParserFree(parser);
    return 0;
}