Insufficient Entropy Vulnerability in libexpat from XML Content Handling
CVE-2026-76956

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-76956?

Versions 2.8.2 and 2.8.3 of libexpat are affected by a flaw wherein the return code of the getentropy function is misinterpreted. This misinterpretation can lead to insufficient entropy being provided during the handling of crafted XML content, making the system vulnerable to hash flooding attacks. This vulnerability can ultimately result in a denial of service, causing service interruptions for users and impacting the overall integrity of applications utilizing the affected library.

Affected Version(s)

libexpat 2.8.2 < 2.8.4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.