CVE-2026-76956

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-20 05:16

Updated : 2026-09-08 21:08


NVD link : CVE-2026-76956

Mitre link : CVE-2026-76956

CVE.ORG link : CVE-2026-76956


JSON object : View

Products Affected

libexpat_project

  • libexpat
CWE
CWE-394

Unexpected Status Code or Return Value