Out-of-bounds read in expat - CVE-2026-72522
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition during Unicode processing in the *_toUtf16 function. A remote attacker can pass specially crafted XML input to the application, trigger an infinite loop and perform a denial of service attack.
Affected software
Debian Linux
openEuler
Fedora
expat
expat-debuginfo
expat-debugsource
expat-devel
expat-help
mingw-expat
expat (Debian package)
How to mitigate CVE-2026-72522
expat - update to 2.8.1-5
expat-debuginfo - update to 2.8.1-5
expat-debugsource - update to 2.8.1-5
expat-devel - update to 2.8.1-5
expat-help - update to 2.8.1-5
mingw-expat - addressed in versions 2.8.3-1.fc43, 2.8.3-1.fc44, 2.8.3-1.fc45
expat (Debian package) - update to 2.8.3-1~deb13u1