Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-93990

Опубликовано: 19 сент. 2026
Источник: debian
EPSS Низкий

Описание

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
expatfixed2.8.4-2package

Примечания

  • https://github.com/libexpat/libexpat/pull/1282

  • Fixed by: https://github.com/libexpat/libexpat/commit/0cfd15bdf4b2c22d6b0df73610709dfb60921091 (R_2_8_5)

  • Fixed by: https://github.com/libexpat/libexpat/commit/28fcfba540f6933aa8904a1514c4811713d2ab72 (R_2_8_5)

EPSS

Процентиль: 28%
0.00347
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

CVSS3: 7.5
redhat
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

CVSS3: 7.5
nvd
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

msrc
4 дня назад

Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate

CVSS3: 7.5
github
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

EPSS

Процентиль: 28%
0.00347
Низкий