CVE-2026-66046: Inefficient Algorithmic Complexity in libexpat project libexpat
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.
AI Analysis
Technical Summary
The vulnerability in libexpat (up to version 2.8.3) is caused by quadratic algorithmic complexity in the storeAtts() function within xmlparse.c. When parsing XML documents containing N specified attributes with non-normalized values, the function performs an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. This inefficiency can be exploited remotely by an unauthenticated attacker who supplies a single well-formed XML document of a few megabytes, leading to excessive CPU consumption and denial of service. The attack does not require authentication, external entity resolution, or non-default parser options.
Potential Impact
A remote unauthenticated attacker can cause a denial of service by sending a specially crafted XML document that triggers excessive CPU consumption due to the quadratic complexity in attribute processing. This results in resource exhaustion and service disruption without needing any privileges or special parser configurations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor communications for updates. Until a fix is available, consider limiting exposure to untrusted XML inputs or applying application-level mitigations to detect and block large or suspicious XML documents.
CVE-2026-66046: Inefficient Algorithmic Complexity in libexpat project libexpat
Description
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.
CVSS v4.0
Score 8.7high
Affected software
libexpat project
libexpat
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in libexpat (up to version 2.8.3) is caused by quadratic algorithmic complexity in the storeAtts() function within xmlparse.c. When parsing XML documents containing N specified attributes with non-normalized values, the function performs an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. This inefficiency can be exploited remotely by an unauthenticated attacker who supplies a single well-formed XML document of a few megabytes, leading to excessive CPU consumption and denial of service. The attack does not require authentication, external entity resolution, or non-default parser options.
Potential Impact
A remote unauthenticated attacker can cause a denial of service by sending a specially crafted XML document that triggers excessive CPU consumption due to the quadratic complexity in attribute processing. This results in resource exhaustion and service disruption without needing any privileges or special parser configurations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor communications for updates. Until a fix is available, consider limiting exposure to untrusted XML inputs or applying application-level mitigations to detect and block large or suspicious XML documents.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-23T20:45:17.817Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a846a46c6e8be033250a62c
Added to database: 08/18/2026, 14:20:54 UTC
Last enriched: 10/02/2026, 15:50:56 UTC
Last updated: 10/03/2026, 14:54:20 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.