CVE Vulnerabilities

CVE-2026-45186

Inefficient Algorithmic Complexity

Published: May 10, 2026 | Modified: May 14, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

Weakness

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Affected Software

NameVendorStart VersionEnd Version
LibexpatLibexpat_project*2.8.1 (excluding)
Red Hat Enterprise Linux 10RedHatexpat-0:2.7.3-1.el10_2.1*
Red Hat Enterprise Linux 8RedHatexpat-0:2.5.0-2.el8_10*
Red Hat Enterprise Linux 9RedHatexpat-0:2.5.0-6.el9_8.1*
Red Hat Enterprise Linux 9RedHatexpat-0:2.5.0-6.el9_8.1*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1781525684*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1781525671*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1781525693*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1781525739*
AyttmUbuntuesm-apps/xenial*
CableswigUbuntuesm-apps/xenial*
CadaverUbuntuesm-apps/xenial*
Coin3Ubuntuesm-apps/xenial*
ExpatUbuntuesm-infra/xenial*
GdcmUbuntuesm-apps/xenial*
Insighttoolkit4Ubuntuesm-apps/xenial*
LibxmltokUbuntuesm-apps/xenial*
MatanzaUbuntudevel*
MatanzaUbuntuesm-apps/focal*
MatanzaUbuntuesm-apps/jammy*
MatanzaUbuntuesm-apps/noble*
MatanzaUbuntuesm-apps/resolute*
MatanzaUbuntuesm-apps/xenial*
MatanzaUbuntujammy*
MatanzaUbuntunoble*
MatanzaUbuntuquesting*
MatanzaUbunturesolute*
SmartUbuntuesm-apps/xenial*
Swish-eUbuntuesm-apps/xenial*
TdomUbuntuesm-apps/xenial*
Vnc4Ubuntuesm-apps/xenial*
VtkUbuntuesm-apps/xenial*
Wbxml2Ubuntuesm-apps/xenial*
Xmlrpc-cUbuntuesm-apps/xenial*

References