CVE-2026-66046
Reported by VulnCheck · Published August 18, 2026
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| libexpat project | libexpat | 0 |
| alpine | expat | 0, 0, 0 |
| libexpat project | libexpat | 0, 0, 0 |
| libexpat_project | libexpat |
Timeline
- Aug 18, 2026 CVE Published
- Aug 20, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 2, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 5, 2026 Security Advisory
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
References
- Pull Request issue-tracking
- third-party-advisory