CVE-2026-45186
2.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Summary
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| libexpat project | libexpat | 0 < 2.8.1 | affected |
Weaknesses
- CWE-407: CWE-407 Inefficient Algorithmic Complexity
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
CVE Program Container
Additional References
libexpat: denial of service via crafted XML input
Additional References
- https://access.redhat.com/security/cve/CVE-2026-45186
- https://bugzilla.redhat.com/show_bug.cgi?id=2468575
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json
- https://access.redhat.com/errata/RHSA-2026:22715
- https://access.redhat.com/errata/RHSA-2026:23230
- https://access.redhat.com/errata/RHSA-2026:22721
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/errata/RHSA-2026:27201
- https://access.redhat.com/errata/RHSA-2026:26319
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.