Insufficient entropy in expat - CVE-2026-41080

 

Insufficient entropy in expat - CVE-2026-41080

Published: April 27, 2026


Vulnerability identifier: #VU128246
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41080
CWE-ID: CWE-331
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to insufficient entropy. A remote attacker can supply a specially crafted XML document and flood hashes, leading to a denial of service condition. 


Affected software

expat
OpenBSD
Ubuntu
openEuler
Fedora
WebSphere Remote Server
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Business Automation Workflow
IBM HTTP Server
IBM OpenPages with Watson
DevOps Code ClearCase
expat (Ubuntu package)
expat-help
expat-devel
expat-debugsource
expat-debuginfo
expat
mingw-expat

How to mitigate CVE-2026-41080

Install updates from vendor's website.

expat - update to 2.8.0
IBM HTTP Server - addressed in versions 8.5.5.30, 9.0.5.28
expat (Ubuntu package) - update to 2.1.0-7ubuntu0.16.04.5+esm12
expat-help - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-devel - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debugsource - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat-debuginfo - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
expat - addressed in versions 2.2.9-25, 2.4.1-24, 2.5.0-18
mingw-expat - addressed in versions 2.8.1-1.fc43, 2.8.1-1.fc44

External References

Related Security Bulletins