Denial of Service Vulnerability in libexpat Affects XML Processing
CVE-2026-45186
2.9LOW
What is CVE-2026-45186?
A vulnerability in libexpat, prior to version 2.8.1, exposes systems to potential denial of service attacks. The issue arises from the computational complexity involved in checking for attribute name collisions, which can be exploited by an attacker through specially crafted XML input. This could lead to resource exhaustion, effectively rendering XML processing capabilities inoperable.
Affected Version(s)
libexpat 0 < 2.8.1
