Insufficient entropy in expat - CVE-2026-41080
Published: April 27, 2026
Vulnerability identifier: #VU128246
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41080
CWE-ID: CWE-331
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to insufficient entropy. A remote attacker can supply a specially crafted XML document and flood hashes, leading to a denial of service condition.
Affected software
expat
Debian Linux
OpenBSD
Ubuntu
openEuler
Fedora
IBM Tivoli Monitoring
WebSphere Remote Server
IBM Rational ClearCase
IBM Rational ClearQuest
IBM Business Automation Workflow
LANTIME Operating System Firmware (LTOS)
IBM HTTP Server
IBM OpenPages with Watson
DevOps Code ClearCase
expat (Ubuntu package)
expat-help
expat-devel
expat-debugsource
expat-debuginfo
expat
mingw-expat
expat (Debian package)
Debian Linux
OpenBSD
Ubuntu
openEuler
Fedora
IBM Tivoli Monitoring
WebSphere Remote Server
IBM Rational ClearCase
IBM Rational ClearQuest
IBM Business Automation Workflow
LANTIME Operating System Firmware (LTOS)
IBM HTTP Server
IBM OpenPages with Watson
DevOps Code ClearCase
expat (Ubuntu package)
expat-help
expat-devel
expat-debugsource
expat-debuginfo
expat
mingw-expat
expat (Debian package)
How to mitigate CVE-2026-41080
Install updates from vendor's website.
expat - update to 2.8.0
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 24
LANTIME Operating System Firmware (LTOS) - update to 7.10.012
IBM HTTP Server - addressed in versions 8.5.5.30, 9.0.5.28
expat (Ubuntu package) - update to 2.1.0-7ubuntu0.16.04.5+esm12
expat-help - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-devel - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debugsource - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debuginfo - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
mingw-expat - addressed in versions 2.8.1-1.fc43, 2.8.1-1.fc44
expat (Debian package) - update to 2.8.2-1~deb13u1
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 24
LANTIME Operating System Firmware (LTOS) - update to 7.10.012
IBM HTTP Server - addressed in versions 8.5.5.30, 9.0.5.28
expat (Ubuntu package) - update to 2.1.0-7ubuntu0.16.04.5+esm12
expat-help - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-devel - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debugsource - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debuginfo - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
mingw-expat - addressed in versions 2.8.1-1.fc43, 2.8.1-1.fc44
expat (Debian package) - update to 2.8.2-1~deb13u1
External References
Related Security Bulletins
- Denial of service in libexpat
- Multiple vulnerabilities in IBM HTTP Server
- OpenBSD update for libexpat
- Fedora 43 update for mingw-expat
- Fedora 44 update for mingw-expat
- Multiple vulnerabilities in IBM Business Automation Workflow
- openEuler 24.03 LTS SP3 update for expat
- openEuler 24.03 LTS SP1 update for expat
- openEuler 24.03 LTS update for expat
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Multiple vulnerabilities in IBM DevOps Code ClearCase
- Multiple vulnerabilities in IBM OpenPages
- openEuler 22.03 LTS SP4 update for expat
- openEuler 20.03 LTS SP4 update for expat
- Multiple vulnerabilities in IBM Rational ClearQuest
- Ubuntu update for expat
- Multiple vulnerabilities in Meinberg LANTIME Operating System Firmware
- Debian update for expat
- IBM Tivoli Monitoring update for libexpat