What is CVE-2026-66046?
Expat through 2.8.3 contains a denial of service vulnerability in the storeAtts() function due to quadratic algorithmic complexity, causing high CPU usage when processing many non-normalized attribute values. Users are advised to update the Expat library to the latest version.
Azərbaycanca: Expat 2.8.3-ə qədər olan versiyalarda storeAtts() funksiyasında O(N^2) mürəkkəbliyinə malik xətti skan nedeniyle denial of service zəifliyi aşkarlanıb. Bu, çoxlu normallaşdırılmamış atribut dəyəri emalı zamanı yüksək CPU istehlakına səbəb ola bilər. İstifadəçilərə Expat kitabxanasını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of the Expat library are affected by CVE-2026-66046?
Versions of the Expat library through 2.8.3 are affected by this vulnerability.
What is the potential impact of CVE-2026-66046?
The vulnerability can cause high CPU usage and a denial of service (DoS) due to quadratic algorithmic complexity in the storeAtts() function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.