Expat XML Parser Vulnerability in Expat Library by Expat Developer
CVE-2026-93990
8.7HIGH
What is CVE-2026-93990?
The Expat Library, up to version 2.8.4, does not adequately validate low surrogates following high surrogates in UTF-16 encoded input. This oversight allows attackers to craft malicious XML that includes lone high surrogates, which can manipulate the parser into accepting malformed UTF-16 sequences. As a result, markup characters can be hidden, potentially leading to XML injection attacks that could compromise application security.
Affected Version(s)
libexpat 0 <= 2.8.4
