CVE-2026-41080
published 2026-04-16CVE-2026-41080: libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
PriorityP412low2.9CVSS 3.1
AVLACHPRNUINSUCNINAL
EPSS
0.40%
32.4th percentile
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| libexpat_project | libexpat | < 2.8.0 | 2.8.0 |
| ubuntu | expat | — | — |
CVSS provenance
nvdv3.12.9LOWCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
libexpat up to 2.7.5 XML Document entropy (ID 47 / EUVD-2026-23276)
vuldb·2026-04-16·CVSS 2.9
CVE-2026-41080 [LOW] libexpat up to 2.7.5 XML Document entropy (ID 47 / EUVD-2026-23276)
A vulnerability categorized as problematic has been discovered in libexpat up to 2.7.5. This impacts an unknown function of the component XML Document Handler. The manipulation results in insufficient entropy.
This vulnerability is known as CVE-2026-41080. Attacking locally is a requirement. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-fpqv-cr66-h6pc: libexpat before 2
ghsa_unreviewed·2026-04-16
CVE-2026-41080 [LOW] CWE-331 GHSA-fpqv-cr66-h6pc: libexpat before 2
libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Ubuntu
Expat vulnerability
vendor_ubuntu·2026-07-09
CVE-2026-41080 Expat vulnerability
Title: Expat vulnerability
Summary: Expat could be made to crash if it received specially crafted input.
It was discovered that Expat used insufficient entropy when generating
hash salt values for its internal hash table. An attacker could use this
to craft an XML document that triggers hash flooding, leading to a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
vendor_redhat·2026-04-16·CVSS 2.9
CVE-2026-41080 [LOW] CWE-331 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing a specially crafted XML document that leverages insufficient entropy in the hash function. This can lead to hash flooding, a type of Denial of Service (DoS) attack, where the system becomes unresponsive or crashes due to excessive resource consumption.
Statement: This Low impact denial of service flaw in libexpat could allow a remote attacker to cause the program consuming libexpat to become unresponsive or crash. This vulnerability requires the processing of a specially crafted XML document, which could lead to excessive resource consumption due to hash flooding.
Mitigation: Applications that process untrusted XML
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41080 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
bugzilla·2026-04-16·CVSS 2.9
CVE-2026-41080 [LOW] CVE-2026-41080 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
CVE-2026-41080 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML
libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Discussion:
Public upstream commit for this issue:
https://github.com/libexpat/libexpat/pull/1183/commits/f5eacefb24a69901a3a608dd4c8697d26cff2c6b
Bugzilla
CVE-2026-41080 expat: libexpat: Denial of Service via hash flooding with crafted XML [fedora-all]
bugzilla·2026-04-16·CVSS 2.9
CVE-2026-41080 [LOW] CVE-2026-41080 expat: libexpat: Denial of Service via hash flooding with crafted XML [fedora-all]
CVE-2026-41080 expat: libexpat: Denial of Service via hash flooding with crafted XML [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41080 mingw-expat: libexpat: Denial of Service via hash flooding with crafted XML [fedora-all]
bugzilla·2026-04-16·CVSS 2.9
CVE-2026-41080 [LOW] CVE-2026-41080 mingw-expat: libexpat: Denial of Service via hash flooding with crafted XML [fedora-all]
CVE-2026-41080 mingw-expat: libexpat: Denial of Service via hash flooding with crafted XML [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
https://blog.hartwork.org/posts/expat-2-8-0-released/https://github.com/libexpat/libexpat/issues/47https://github.com/libexpat/libexpat/pull/1183https://www.openwall.com/lists/oss-security/2026/04/26/1http://www.openwall.com/lists/oss-security/2026/04/26/1https://cert-portal.siemens.com/productcert/html/ssa-082556.html
2026-04-16
Published