Denial of Service Vulnerability in libexpat Affects XML Processing
CVE-2026-45186

2.9LOW

Key Information:

Status
Vendor
CVE Published:
10 May 2026

What is CVE-2026-45186?

A vulnerability in libexpat, prior to version 2.8.1, exposes systems to potential denial of service attacks. The issue arises from the computational complexity involved in checking for attribute name collisions, which can be exploited by an attacker through specially crafted XML input. This could lead to resource exhaustion, effectively rendering XML processing capabilities inoperable.

Affected Version(s)

libexpat 0 < 2.8.1

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.