Insufficient entropy in expat - CVE-2026-41080

 

Insufficient entropy in expat - CVE-2026-41080

Published: April 27, 2026


Vulnerability identifier: #VU128246
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41080
CWE-ID: CWE-331
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to insufficient entropy. A remote attacker can supply a specially crafted XML document and flood hashes, leading to a denial of service condition. 


Affected software

expat
Debian Linux
OpenBSD
Ubuntu
openEuler
Fedora
IBM Tivoli Monitoring
WebSphere Remote Server
IBM Rational ClearCase
IBM Rational ClearQuest
IBM Business Automation Workflow
LANTIME Operating System Firmware (LTOS)
IBM HTTP Server
IBM OpenPages with Watson
DevOps Code ClearCase
expat (Ubuntu package)
expat-help
expat-devel
expat-debugsource
expat-debuginfo
expat
mingw-expat
expat (Debian package)

How to mitigate CVE-2026-41080

Install updates from vendor's website.

expat - update to 2.8.0
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 24
LANTIME Operating System Firmware (LTOS) - update to 7.10.012
IBM HTTP Server - addressed in versions 8.5.5.30, 9.0.5.28
expat (Ubuntu package) - update to 2.1.0-7ubuntu0.16.04.5+esm12
expat-help - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-devel - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debugsource - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debuginfo - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
mingw-expat - addressed in versions 2.8.1-1.fc43, 2.8.1-1.fc44
expat (Debian package) - update to 2.8.2-1~deb13u1

External References

Related Security Bulletins