CVE-2026-45186

high
Published 2026-05-10 Β· Modified 2026-06-03
CVSS v3
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
7.5

Description

RHSA-2026:22721: expat security update (Important)

Predictions

Exploit likelihood
83%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description libexpat: denial of service via crafted XML input Red Hat statement To exploit this issue, an attacker needs to be able to process a specially crafted XML file or input with an application linked to the libexpat library. Also, the only security impact of this flaw is a high consumption of CPU resources that can eventually cause a denial of service. Due to this reason, this…

Description

libexpat: denial of service via crafted XML input

Red Hat statement

To exploit this issue, an attacker needs to be able to process a specially crafted XML file or input with an application linked to the libexpat library. Also, the only security impact of this flaw is a high consumption of CPU resources that can eventually cause a denial of service. Due to this reason, this vulnerability has been rated with an important severity.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Package state

ProductPackageState
Red Hat Enterprise Linux 10expatAffected
Red Hat Enterprise Linux 6compat-expat1Affected
Red Hat Enterprise Linux 6expatWill not fix
Red Hat Enterprise Linux 7expatAffected
Red Hat Enterprise Linux 8expatAffected
Red Hat Enterprise Linux 8mingw-expatAffected
Red Hat Enterprise Linux 9expatAffected
Red Hat JBoss Core Serviceslibexpat-2.dllAffected

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat JBoss Core ServicesAffected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
windows Windows Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected β€”
sid Fixed 2.8.0-2
forky Fixed 2.8.0-2
bullseye Affected β€”
bookworm Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
8 Fixed expat-devel-2.5.0-2.el8_10.i686.rpm
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

Application impact

VendorProductVersionsFixed
libexpat_projectlibexpat{"endExcluding":"2.8.1"}2.8.1

References

CWEs

CWE-407

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.