CVE-2026-41080: Libexpat Project Libexpat
Low severity, CVSS 2.9. EPSS: 0.4% chance of exploitation in the next 30 days.
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Affected products
- Libexpat Project Libexpat: before 2.8.0 (fixed in 2.8.0)
Published 2026-04-16. Last modified 2026-07-14.