CVE-2026-41080: libexpat 2.8.0 fixes CVE-2026-41080 (insufficient entropy)
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.8.2-1 - Upgrade
Upgrade
libexpatto a version that resolves this vulnerability.Fixed in 2.8.0 - Compensating control
Mitigate potential hash flooding by preventing or filtering untrusted XML documents until libexpat is upgraded to 2.8.0.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41080?
CVE-2026-41080 has been classified as a moderate severity vulnerability due to the potential for hash flooding attacks.
How do I fix CVE-2026-41080?
To mitigate CVE-2026-41080, upgrade to libexpat version 2.7.6 or later.
What type of attacks are possible with CVE-2026-41080?
CVE-2026-41080 may lead to denial of service attacks through hash flooding via crafted XML documents.
Which versions of libexpat are affected by CVE-2026-41080?
Versions of libexpat prior to 2.7.6 are affected by CVE-2026-41080.
Is CVE-2026-41080 exploitable in production environments?
Yes, CVE-2026-41080 could potentially be exploited in production environments that process untrusted XML data.