Issued at: 2026-09-29
Updated at: 2026-09-29
Advisory content derived from Red Hat RHSA-2026:72448, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: expat security update
Description
Expat is a C library for parsing XML documents.
Security Fix(es):
* expat: Expat: Denial of Service via quadratic complexity in attribute processing (CVE-2026-66046)
* expat: Expat: XML Injection via Malformed UTF-16 Input (CVE-2026-93990)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.