Insufficient Entropy Vulnerability in libexpat from XML Content Handling
CVE-2026-76956

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-76956?

Versions 2.8.2 and 2.8.3 of libexpat are affected by a flaw wherein the return code of the getentropy function is misinterpreted. This misinterpretation can lead to insufficient entropy being provided during the handling of crafted XML content, making the system vulnerable to hash flooding attacks. This vulnerability can ultimately result in a denial of service, causing service interruptions for users and impacting the overall integrity of applications utilizing the affected library.

Affected Version(s)

libexpat 2.8.2 < 2.8.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.