xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-8604.json"