In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
Low CVSS 2.9
Summary
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/libexpat/libexpat/pull/1216 Exploit
- http://www.openwall.com/lists/oss-security/2026/05/11/16 Mailing List
- https://access.redhat.com/errata/RHSA-2026:22715
- https://access.redhat.com/errata/RHSA-2026:22721
- https://access.redhat.com/errata/RHSA-2026:23230
- https://access.redhat.com/errata/RHSA-2026:26319
- https://access.redhat.com/errata/RHSA-2026:27201
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/errata/RHSA-2026:58981
- https://access.redhat.com/security/cve/CVE-2026-45186
- https://bugzilla.redhat.com/show_bug.cgi?id=2468575
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json
Timeline
- nvd_ingest NVD