CVE-2026-41080

· NIST NVD ↗

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

LOW
CVSS severity
2.9
CVSS base score
2026-04-16
Published

CWE codes

CWE-331

Affected products

libexpat_project:libexpat

Sources