Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-93990

Опубликовано: 19 сент. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

EPSS

Процентиль: 28%
0.00347
Низкий

7.5 High

CVSS3

Дефекты

CWE-176

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

CVSS3: 7.5
redhat
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

msrc
4 дня назад

Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate

CVSS3: 7.5
debian
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high su ...

CVSS3: 7.5
github
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

EPSS

Процентиль: 28%
0.00347
Низкий

7.5 High

CVSS3

Дефекты

CWE-176