Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rfp9-ffqc-h4x8

Опубликовано: 20 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

EPSS

Процентиль: 28%
0.00347
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-176

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

CVSS3: 7.5
redhat
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

CVSS3: 7.5
nvd
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

msrc
4 дня назад

Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate

CVSS3: 7.5
debian
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high su ...

EPSS

Процентиль: 28%
0.00347
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-176