CVE Vulnerabilities

CVE-2026-41080

Insufficient Entropy

Published: Apr 16, 2026 | Modified: Jun 12, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

Weakness

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Affected Software

NameVendorStart VersionEnd Version
LibexpatLibexpat_project*2.8.0 (excluding)
Red Hat Hardened ImagesRedHatexpat-main-2.8.0-0.1.hum1*
AyttmUbuntuesm-apps/xenial*
CableswigUbuntuesm-apps/xenial*
CadaverUbuntuesm-apps/xenial*
Coin3Ubuntuesm-apps/xenial*
ExpatUbuntuesm-infra/xenial*
GdcmUbuntuesm-apps/xenial*
Insighttoolkit4Ubuntuesm-apps/xenial*
LibxmltokUbuntuesm-apps/xenial*
MatanzaUbuntudevel*
MatanzaUbuntuesm-apps/focal*
MatanzaUbuntuesm-apps/jammy*
MatanzaUbuntuesm-apps/noble*
MatanzaUbuntuesm-apps/resolute*
MatanzaUbuntuesm-apps/xenial*
MatanzaUbuntujammy*
MatanzaUbuntunoble*
MatanzaUbuntuquesting*
MatanzaUbunturesolute*
SmartUbuntuesm-apps/xenial*
Swish-eUbuntuesm-apps/xenial*
TdomUbuntuesm-apps/xenial*
Vnc4Ubuntuesm-apps/xenial*
VtkUbuntuesm-apps/xenial*
Wbxml2Ubuntuesm-apps/xenial*
Xmlrpc-cUbuntuesm-apps/xenial*

Potential Mitigations

References