libexpat 2.8.5 fixes CVE-2026-93990 (malformed UTF-16 smuggling)
libexpat 2.8.5 fixes CVE-2026-93990 by rejecting malformed UTF-16 that could be smuggled into applications.
Sebastian Pipping announced that libexpat 2.8.5, also called Expat 2.8.5, fixes CVE-2026-93990. The release rejects high UTF-16 surrogates that are not followed by a low surrogate. Previously, malformed UTF-16 could be passed into applications using Expat, where the application's handling could cause arbitrary damage. The note does not report observed exploitation.
58