Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-93990

Опубликовано: 21 сент. 2026
Источник: msrc
CVSS3: 7.5
EPSS Низкий

Описание

Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate

Обновления

ПродуктСтатьяОбновление
azl3 expat 2.8.3-2 on Azure Linux 3.0

Показывать по

EPSS

Процентиль: 28%
0.00347
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

CVSS3: 7.5
redhat
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

CVSS3: 7.5
nvd
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

CVSS3: 7.5
debian
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high su ...

CVSS3: 7.5
github
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

EPSS

Процентиль: 28%
0.00347
Низкий

7.5 High

CVSS3