PT-2026-33342 · Libexpat+1 · Libexpat+1

·

CVE-2026-41080

·

Published

2026-04-16

·

Updated

2026-07-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions libexpat versions prior to 2.7.6
Description The software uses insufficient entropy, which allows hash flooding to occur through a specially crafted XML document. Hash flooding is a technique where many different inputs are designed to produce the same hash value, causing a collision that degrades the performance of hash tables.
Recommendations Update to version 2.7.6.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-ID74762
CLEANSTART-2026-LN45890
CLEANSTART-2026-MM40347
CLEANSTART-2026-OM32721
CLEANSTART-2026-UP30431
CLEANSTART-2026-XA09439
CLEANSTART-2026-ZL11893
CVE-2026-41080
ECHO-35D6-A603-460E
OESA-2026-2293
OESA-2026-2294
OESA-2026-2295
OESA-2026-2498
OESA-2026-2499
OPENSUSE-SU-2026:10787-1
RHSA-2026:11004
USN-8520-1

Affected Products

Ibm Aix
Libexpat