CVE-2026-76956
EUVD-2026-6319520.08.2026, 05:16
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| libexpat_project | libexpat | 2.8.2 ≤ 𝑥 < 2.8.4 | CNA |
Debian Releases
Common Weakness Enumeration
Vulnerability Media Exposure