libexpat vulnerability

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

Published 10 May 2026Updated 16 Sep 202615 sources
CVSS 2.9 ✓ VERIFIED REFERENCE

What happened

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

Affected versions

libexpat: before 2.8.1 (semver); V3.1.5 through before V3.1.6 (custom) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

RepositoryAuthorFirst seenReference
github.comNVD reference2026-05-10Verified