CVE-2026-45186 Details
Description
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
A denial-of-service vulnerability has been identified in libexpat versions prior to 2.8.1. The issue arises from the computational complexity involved in checking for collisions in attribute names, which can be exploited using moderately sized crafted XML input.
Users can upgrade to libexpat version 2.8.1 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:22715 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:22721 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:23230 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:26319 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:27201 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:29197 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:58981 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-45186 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2468575 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json | redhat-SADP | |
| https://cert-portal.siemens.com/productcert/html/ssa-082556.html | siemens-SADP | |
| http://www.openwall.com/lists/oss-security/2026/05/11/16 | CVE | Mailing ListThird Party Advisory |
| https://github.com/libexpat/libexpat/pull/1216 | [email protected] | ExploitIssue TrackingPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-407 | Inefficient Algorithmic Complexity | redhat-SADP |
| CWE-407 | Inefficient Algorithmic Complexity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libexpat project libexpat | < 2.8.1 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | [email protected] |
| Sep 16, 2026 | CVE Modified | CVE |
| Sep 16, 2026 | CVE Modified | redhat-SADP |
| Sep 16, 2026 | CVE Modified | siemens-SADP |
| Aug 25, 2026 | CVE Modified | redhat-SADP |
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 14, 2026 | CVE Modified | siemens-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | Initial Analysis | [email protected] |
| May 11, 2026 | CVE Modified | CVE |
| May 10, 2026 | New CVE Received | [email protected] |