HIGH
libexpat
CVE published 2026-09-19
CVE-2026-93990
The CVE-2026-93990 vulnerability in Expat through 2.8.4 allows malformed UTF-16 sequences to be accepted, enabling XML injection attacks. This issue arises from the failure to validate low surrogates following high surrogates in UTF-16 input. The vulnerability impacts systems that utilize Expat for XML parsing, particularly those with untrusted input. Defenders should assess exposure and prioritize verifi [truncated]