Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libexpat Project
Libexpat Project libexpat |
|
| Vendors & Products |
Libexpat Project
Libexpat Project libexpat |
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options. | |
| Title | Expat Denial of Service via storeAtts() Quadratic Complexity | |
| Weaknesses | CWE-407 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T14:10:05.176Z
Reserved: 2026-07-23T20:45:17.817Z
Link: CVE-2026-66046
No data.
Status : Received
Published: 2026-08-18T15:16:57.000
Modified: 2026-08-18T15:16:57.000
Link: CVE-2026-66046
No data.
OpenCVE Enrichment
Updated: 2026-08-18T16:15:04Z
-
CWE-407
Inefficient Algorithmic Complexity