Insufficient Entropy Vulnerability in libexpat Affects Multiple Versions
CVE-2026-41080

2.9LOW

Key Information:

Status
Vendor
CVE Published:
16 April 2026

What is CVE-2026-41080?

The libexpat library, used extensively for parsing XML documents, is susceptible to a vulnerability due to insufficient entropy. This can lead to hash flooding when an attacker utilizes a specially crafted XML document, disrupting the normal service operation and potentially allowing for denial of service conditions. It is crucial for users of affected versions to update to version 2.7.6 or later to mitigate this risk.

Affected Version(s)

libexpat 0 < 2.7.6

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.