Out-of-Bounds Read in Libexpat Affects Multiple Vendors
CVE-2026-72522

6.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72522?

A vulnerability in libexpat allows for an out-of-bounds read due to improper handling of low surrogates compared to high surrogates during Unicode processing in the *_toUtf16 functions. This flaw can result in unexpected behavior, including a potential infinite loop, affecting the performance and stability of applications relying on this library.

Affected Version(s)

libexpat 0 < 2.8.3

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.