CVE-2026-45186: Libexpat Project Libexpat

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

Affected products

Published 2026-05-10. Last modified 2026-09-16.