Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-93990

Опубликовано: 19 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

A flaw was found in Expat. This vulnerability allows a remote attacker to send specially crafted UTF-16 encoded XML data. Due to improper validation of surrogate characters, the parser can be tricked into accepting malformed sequences, which can hide legitimate markup characters. This could enable XML injection attacks, potentially leading to information disclosure or other integrity impacts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-91
https://bugzilla.redhat.com/show_bug.cgi?id=2538967expat: Expat: XML Injection via Malformed UTF-16 Input

EPSS

Процентиль: 28%
0.00347
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

CVSS3: 7.5
nvd
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

msrc
4 дня назад

Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate

CVSS3: 7.5
debian
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high su ...

CVSS3: 7.5
github
5 дней назад

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

EPSS

Процентиль: 28%
0.00347
Низкий

7.5 High

CVSS3