Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks. | |
| Title | Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate | |
| First Time appeared |
Libexpat Project
Libexpat Project libexpat |
|
| Weaknesses | CWE-176 | |
| CPEs | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libexpat Project
Libexpat Project libexpat |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-19T22:58:11.224Z
Reserved: 2026-09-19T10:55:49.093Z
Link: CVE-2026-93990
No data.
Status : Received
Published: 2026-09-19T23:17:10.203
Modified: 2026-09-19T23:17:10.203
Link: CVE-2026-93990
No data.
OpenCVE Enrichment
Updated: 2026-09-20T01:15:07Z
