In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
References
| Link | Resource |
|---|---|
| https://github.com/libexpat/libexpat/pull/1326 | Issue Tracking Patch |
| https://github.com/libexpat/libexpat/pull/1329 | Issue Tracking Patch |
Configurations
History
No history.
Information
Published : 2026-08-20 05:16
Updated : 2026-09-08 21:08
NVD link : CVE-2026-76956
Mitre link : CVE-2026-76956
CVE.ORG link : CVE-2026-76956
JSON object : View
Products Affected
libexpat_project
- libexpat
CWE
CWE-394
Unexpected Status Code or Return Value
