ZeroHour

CVE-2026-76956

CVSS 3.1
7.5 high
EPSS
<1%p21
Published
()
Modified
Description

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

Vendors
libexpat project
Products
libexpat
Weakness
CWE-394
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.