CVE-2026-76956

Summary

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

Affected Software

VendorProductVersion RangeStatus
libexpat projectlibexpat2.8.2 < 2.8.4affected

Weaknesses

  • CWE-394: CWE-394 Unexpected Status Code or Return Value

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References