CVE Vulnerabilities

CVE-2026-76956

Unexpected Status Code or Return Value

Published: Aug 20, 2026 | Modified: Sep 08, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropys return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

Weakness

The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.

Affected Software

NameVendorStart VersionEnd Version
LibexpatLibexpat_project2.8.2 (including)2.8.4 (excluding)
Red Hat Hardened ImagesRedHatexpat-main-2.8.3-0.1.1.hum1*
Red Hat Hardened ImagesRedHatexpat-main-2.8.4-0.1.hum1*
ExpatUbuntudevel*
ExpatUbuntuupstream*
MatanzaUbuntudevel*
MatanzaUbuntuesm-apps/focal*
MatanzaUbuntuesm-apps/jammy*
MatanzaUbuntuesm-apps/noble*
MatanzaUbuntuesm-apps/resolute*
MatanzaUbuntujammy*
MatanzaUbuntunoble*
MatanzaUbunturesolute*

References