Insufficient entropy in expat - CVE-2026-41080
Published: April 27, 2026
Vulnerability identifier: #VU128246
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41080
CWE-ID: CWE-331
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to insufficient entropy. A remote attacker can supply a specially crafted XML document and flood hashes, leading to a denial of service condition.
Affected software
expat
OpenBSD
Ubuntu
openEuler
Fedora
WebSphere Remote Server
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Business Automation Workflow
IBM HTTP Server
IBM OpenPages with Watson
DevOps Code ClearCase
expat (Ubuntu package)
expat-help
expat-devel
expat-debugsource
expat-debuginfo
expat
mingw-expat
OpenBSD
Ubuntu
openEuler
Fedora
WebSphere Remote Server
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Business Automation Workflow
IBM HTTP Server
IBM OpenPages with Watson
DevOps Code ClearCase
expat (Ubuntu package)
expat-help
expat-devel
expat-debugsource
expat-debuginfo
expat
mingw-expat
How to mitigate CVE-2026-41080
Install updates from vendor's website.
expat - update to 2.8.0
IBM HTTP Server - addressed in versions 8.5.5.30, 9.0.5.28
expat (Ubuntu package) - update to 2.1.0-7ubuntu0.16.04.5+esm12
expat-help - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-devel - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debugsource - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debuginfo - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
mingw-expat - addressed in versions 2.8.1-1.fc43, 2.8.1-1.fc44
IBM HTTP Server - addressed in versions 8.5.5.30, 9.0.5.28
expat (Ubuntu package) - update to 2.1.0-7ubuntu0.16.04.5+esm12
expat-help - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-devel - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debugsource - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debuginfo - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
mingw-expat - addressed in versions 2.8.1-1.fc43, 2.8.1-1.fc44
External References
Related Security Bulletins
- Denial of service in libexpat
- Multiple vulnerabilities in IBM HTTP Server
- OpenBSD update for libexpat
- Fedora 43 update for mingw-expat
- Fedora 44 update for mingw-expat
- Multiple vulnerabilities in IBM Business Automation Workflow
- openEuler 24.03 LTS SP3 update for expat
- openEuler 24.03 LTS SP1 update for expat
- openEuler 24.03 LTS update for expat
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Multiple vulnerabilities in IBM DevOps Code ClearCase
- Multiple vulnerabilities in IBM OpenPages
- openEuler 22.03 LTS SP4 update for expat
- openEuler 20.03 LTS SP4 update for expat
- Multiple vulnerabilities in IBM Rational ClearQuest
- Ubuntu update for expat