Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45186

Опубликовано: 10 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

A flaw was found in libexpat. When processing a specially crafted XML input containing a specific pattern of attributes, the parsing time increases quadratically due to checks for attribute name collisions. This consumes excessive CPU resources and eventually results in a denial of service.

Отчет

To exploit this issue, an attacker needs to be able to process a specially crafted XML file or input with an application linked to the libexpat library. Also, the only security impact of this flaw is a high consumption of CPU resources that can eventually cause a denial of service. Due to this reason, this vulnerability has been rated with an important severity.

Меры по смягчению последствий

To mitigate this vulnerability, restrict the maximum size of incoming XML payloads. It is especially critical to limit the decompressed size if the application accepts compressed XML files. Also, consider running the application inside a container or a restricted environment to ensure that the high consumption of CPU resources does not affect the host system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6compat-expat1Affected
Red Hat Enterprise Linux 6expatWill not fix
Red Hat Enterprise Linux 7expatAffected
Red Hat Enterprise Linux 8mingw-expatAffected
Red Hat Enterprise Linux 10expatFixedRHSA-2026:2271503.06.2026
Red Hat Enterprise Linux 8expatFixedRHSA-2026:2272103.06.2026
Red Hat Enterprise Linux 9expatFixedRHSA-2026:2323004.06.2026
Red Hat Enterprise Linux 9expatFixedRHSA-2026:2323004.06.2026
Red Hat JBoss Core Services 2.4.62.SP4libexpat-2.dllFixedRHSA-2026:2720122.06.2026
Red Hat Discovery 2discovery/discovery-server-rhel9FixedRHSA-2026:2919724.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-407
https://bugzilla.redhat.com/show_bug.cgi?id=2468575libexpat: denial of service via crafted XML input

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
3 месяца назад

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

CVSS3: 2.9
nvd
3 месяца назад

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

CVSS3: 2.9
msrc
3 месяца назад

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

CVSS3: 2.9
debian
3 месяца назад

In libexpat before 2.8.1, the computational complexity of attribute na ...

rocky
около 2 месяцев назад

Important: expat security update

7.5 High

CVSS3