Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96605.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-96605
Upstream
Published
2026-08-18T15:16:57Z
Modified
2026-08-28T17:48:14.829995456Z
Summary
CVE-2026-66046 affecting package expat 2.8.2-1
Details

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.

References

Affected packages

Azure Linux:3 / expat

Package

Name
expat
Purl
pkg:rpm/azure-linux/expat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.8.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96605.json"