Deployments that parse attacker-controlled XML are exposed, including remotely reachable services. The supplied CVSS vector for these issues indicates network exploitation with no privileges or user interaction required.
Yes. A compression layer around XML can significantly reduce the minimum size of the crafted payload needed to trigger the quadratic-runtime condition.
It is relevant in configurations where getentropy is configured or detected as the only high-quality entropy extractor. In that case, inverted getentropy return handling could allow hash-flooding denial of service.
Yes. CVE-2026-76957 concerns parser re-entry through custom encoding callbacks. The release protects those callbacks from parser re-entry.
libexpat 2.8.4 fixes CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, and CVE-2026-76957.