CVE-2026-76956
published 2026-08-20CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.29%
21.1th percentile
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | — | — |
| libexpat_project | libexpat | >= 2.8.2 < 2.8.4 | 2.8.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
libexpat project Libexpat up to 2.8.3 denial of service (WID-SEC-2026-2944)
vuldb·2026-09-06·CVSS 5.9
CVE-2026-76956 [MEDIUM] libexpat project Libexpat up to 2.8.3 denial of service (WID-SEC-2026-2944)
A vulnerability classified as problematic was found in libexpat project Libexpat up to 2.8.3. Impacted is an unknown function. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2026-76956. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of s
ghsa_unreviewed·2026-08-20
CVE-2026-76956 [HIGH] CWE-394 In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of s
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
Red Hat
libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML
vendor_redhat·2026-08-20·CVSS 5.9
CVE-2026-76956 [MEDIUM] CWE-331 libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML
libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
A flaw was found in libexpat. This vulnerability arises from the software misinterpreting a return code, leading to insufficient randomness (entropy) for hash functions. A remote attacker could exploit this by sending specially crafted XML content, triggering hash flooding attacks. This can result in a denial of service (DoS), making the affected system or application unavailable to legitimate users.
Statement: Red Hat ships libexpat (packaged as "expat") across many products. Thi
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-76956 mingw-expat: libexpat: Denial of Service via hash flooding attack with crafted XML [fedora-all]
bugzilla·2026-08-26·CVSS 5.9
CVE-2026-76956 [MEDIUM] CVE-2026-76956 mingw-expat: libexpat: Denial of Service via hash flooding attack with crafted XML [fedora-all]
CVE-2026-76956 mingw-expat: libexpat: Denial of Service via hash flooding attack with crafted XML [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
Bugzilla
CVE-2026-76956 libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML
bugzilla·2026-08-20·CVSS 5.9
CVE-2026-76956 [MEDIUM] CVE-2026-76956 libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML
CVE-2026-76956 libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
2026-08-20
Published