CVE-2026-45186: Libexpat Project Libexpat
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
Affected products
- Libexpat Project Libexpat: before 2.8.1 (fixed in 2.8.1)
Published 2026-05-10. Last modified 2026-09-16.