Expat · Expat · CVE-2026-93990
**Name of the Vulnerable Software and Affected Versions**
Expat versions prior to 2.8.5
**Description**
The software fails to validate low surrogates following high surrogates in UTF-16 input, which allows malformed UTF-16 sequences to be accepted. This behavior enables attackers to craft UTF-16 encoded XML containing lone high surrogates that consume subsequent code units. Consequently, markup characters can be hidden from the parser, facilitating XML injection attacks.
**Recommendations**
Update to version 2.8.5 or later.