Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x282-q22w-c9hm

Опубликовано: 20 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

EPSS

Процентиль: 16%
0.0025
Низкий

7.5 High

CVSS3

Дефекты

CWE-394

Связанные уязвимости

CVSS3: 5.9
ubuntu
7 дней назад

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

CVSS3: 5.9
nvd
8 дней назад

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

msrc
6 дней назад

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

CVSS3: 5.9
debian
8 дней назад

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentr ...

EPSS

Процентиль: 16%
0.0025
Низкий

7.5 High

CVSS3

Дефекты

CWE-394