libexpat vulnerability

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

Published 10 May 2026Updated 16 Sep 202618 sources
CVSS 2.9 ✓ VERIFIED REFERENCE

Source timeline

CVE record published by NVDView source ↗