What is CVE-2026-72522?
This vulnerability in libexpat versions before 2.8.3 involves an out-of-bounds read leading to an infinite loop due to improper handling of high and low surrogates during Unicode processing in the *_toUtf16 functions. It can cause a denial of service (DoS) on affected systems, so updating to version 2.8.3 is strongly recommended.
Azərbaycanca: Bu boşluq libexpat kitabxanasının 2.8.3 versiyasından əvvəlki versiyalarında Unicode emalı zamanı yaranan `out-of-bounds read` qüsurudur ki, bu da sonsuz dövr (infinite loop) ilə nəticələnir. Təsirə məruz qalan sistemlərdə xidmət rəddi (DoS) hücumlarına səbəb ola bilər, dərhal kitabxananı 2.8.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
What issue does CVE-2026-72522 in the libexpat library cause?
This vulnerability is an out-of-bounds read during Unicode processing that leads to an infinite loop, potentially causing a denial of service (DoS).
To which version should the libexpat library be updated to protect against CVE-2026-72522?
It is recommended to update the libexpat library to version 2.8.3 to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.