Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41080

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing a specially crafted XML document that leverages insufficient entropy in the hash function. This can lead to hash flooding, a type of Denial of Service (DoS) attack, where the system becomes unresponsive or crashes due to excessive resource consumption.

Отчет

This Low impact denial of service flaw in libexpat could allow a remote attacker to cause the program consuming libexpat to become unresponsive or crash. This vulnerability requires the processing of a specially crafted XML document, which could lead to excessive resource consumption due to hash flooding.

Меры по смягчению последствий

Applications that process untrusted XML documents using libexpat should implement robust input validation to filter out malicious XML structures. Restricting access to services that process untrusted XML can also reduce the attack surface. If a service is affected, restarting it may be required after implementing input validation or access restrictions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10expatFix deferred
Red Hat Enterprise Linux 6compat-expat1Fix deferred
Red Hat Enterprise Linux 6expatFix deferred
Red Hat Enterprise Linux 7expatFix deferred
Red Hat Enterprise Linux 8expatFix deferred
Red Hat Enterprise Linux 8mingw-expatFix deferred
Red Hat Enterprise Linux 9expatFix deferred
Red Hat Hardened Imagesexpat-main-2.8.0-0.1.hum1FixedRHSA-2026:1100427.04.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-331
https://bugzilla.redhat.com/show_bug.cgi?id=2458967libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML

EPSS

Процентиль: 33%
0.00398
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
4 месяца назад

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

CVSS3: 2.9
nvd
4 месяца назад

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

msrc
3 месяца назад

Описание отсутствует

CVSS3: 2.9
debian
4 месяца назад

libexpat before 2.8.0 uses insufficient entropy, and thus hash floodin ...

CVSS3: 2.9
github
4 месяца назад

libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

EPSS

Процентиль: 33%
0.00398
Низкий

3.7 Low

CVSS3