REDHAT-BUG-2468575: High severity Expat libexpat vulnerability
Published May 10, 2026
·Updated
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
Affected Software
1 affected component
Expat libexpat<2.8.1
Event History
May 10, 2026
Data Sourced
via Red Hat·07:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2468575?
The severity of REDHAT-BUG-2468575 is rated as high with a score of 7.
2
What is the description of REDHAT-BUG-2468575?
REDHAT-BUG-2468575 describes a vulnerability in libexpat before version 2.8.1 that can lead to a denial of service via crafted XML input.
3
How do I fix REDHAT-BUG-2468575?
To fix REDHAT-BUG-2468575, upgrade to libexpat version 2.8.1 or later.
4
What type of vulnerability is REDHAT-BUG-2468575?
REDHAT-BUG-2468575 is a denial of service vulnerability due to computational complexity issues in attribute name collision checks.
5
What software is affected by REDHAT-BUG-2468575?
The affected software by REDHAT-BUG-2468575 is the Expat library, specifically libexpat.