7.5
CVE-2026-41080
- EPSS 0.4%
- Veröffentlicht 16.04.2026 16:52:01
- Zuletzt bearbeitet 14.07.2026 13:18:51
- Erkennungen
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libexpat Project ≫ Libexpat Version < 2.8.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.321 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 2.9 | 1.4 | 1.4 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-331 Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
https://github.com/libexpat/libexpat/pull/1183
https://github.com/libexpat/libexpat/issues/47
http://www.openwall.com/lists/oss-security/2026/04/26/1
https://blog.hartwork.org/posts/expat-2-8-0-released/
https://www.openwall.com/lists/oss-security/2026/04/26/1
https://cert-portal.siemens.com/productcert/html/ssa-082556.html