PT-2026-95874 · Expat+1 · Expat+1

·

CVE-2026-93990

·

Published

2026-09-19

·

Updated

2026-09-28

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Expat versions prior to 2.8.5
Description The software fails to validate low surrogates following high surrogates in UTF-16 input, which allows malformed UTF-16 sequences to be accepted. This behavior enables attackers to craft UTF-16 encoded XML containing lone high surrogates that consume subsequent code units. Consequently, markup characters can be hidden from the parser, facilitating XML injection attacks.
Recommendations Update to version 2.8.5 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:72448
AZL-103316
CVE-2026-93990
ECHO-41D9-8113-CE4D

Affected Products

Expat
Rocky Linux