CVE-2026-41080: libexpat 2.8.0 fixes CVE-2026-41080 (insufficient entropy)
Last updated 21 September 2026
Other sources
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.8.2-1 - Upgrade
Upgrade
debian/expatto a version that resolves this vulnerability.Fixed in 2.8.3-1~deb13u1Fixed in 2.8.4-1Fixed in 2.8.4-2 - Upgrade
Upgrade
libexpatto a version that resolves this vulnerability.Fixed in 2.8.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41080?
CVE-2026-41080 has been classified as a moderate severity vulnerability due to the potential for hash flooding attacks.
How do I fix CVE-2026-41080?
To mitigate CVE-2026-41080, upgrade to libexpat version 2.7.6 or later.
What type of attacks are possible with CVE-2026-41080?
CVE-2026-41080 may lead to denial of service attacks through hash flooding via crafted XML documents.
Which versions of libexpat are affected by CVE-2026-41080?
Versions of libexpat prior to 2.7.6 are affected by CVE-2026-41080.
Is CVE-2026-41080 exploitable in production environments?
Yes, CVE-2026-41080 could potentially be exploited in production environments that process untrusted XML data.