Inefficient Algorithmic Complexity in expat - CVE-2026-76641
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an inefficient algorithm in attribute isCdata lookups when parsing crafted XML input. A remote attacker can submit moderately sized crafted XML input to cause a denial of service.
A compression layer around XML can significantly reduce the minimum attack payload size.
Affected software
openEuler
expat-help
expat-devel
expat-debugsource
expat-debuginfo
expat
How to mitigate CVE-2026-76641
expat-help - addressed in versions 2.2.9-33, 2.4.1-31, 2.5.0-27, 2.8.1-8
expat-devel - addressed in versions 2.2.9-33, 2.4.1-31, 2.5.0-27, 2.8.1-8
expat-debugsource - addressed in versions 2.2.9-33, 2.4.1-31, 2.5.0-27, 2.8.1-8
expat-debuginfo - addressed in versions 2.2.9-33, 2.4.1-31, 2.5.0-27, 2.8.1-8
expat - addressed in versions 2.2.9-33, 2.4.1-31, 2.5.0-27, 2.8.1-8