CVE-2026-45186: libexpat 2.8.1 fixes CVE-2026-45186 (denial of service)
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.8.2-1 - Upgrade
Upgrade
debian/expatto a version that resolves this vulnerability.Fixed in 2.8.3-1~deb13u1Fixed in 2.8.4-1Fixed in 2.8.4-2 - Upgrade
Upgrade
libexpatto a version that resolves this vulnerability.Fixed in 2.8.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45186?
CVE-2026-45186 is classified as a denial of service vulnerability.
How do I fix CVE-2026-45186?
To mitigate CVE-2026-45186, upgrade to libexpat version 2.8.1 or later.
What are the risks associated with CVE-2026-45186?
The risks include potential service downtime due to the careful crafting of XML input.
Which versions of libexpat are affected by CVE-2026-45186?
CVE-2026-45186 affects libexpat versions prior to 2.8.1.
Can CVE-2026-45186 impact production environments?
Yes, if exploited, CVE-2026-45186 can lead to service interruptions in production environments.