CVE-2026-41080: Libexpat Project Libexpat

Low severity, CVSS 2.9. EPSS: 0.4% chance of exploitation in the next 30 days.

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

Affected products

Published 2026-04-16. Last modified 2026-07-14.