Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96605.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-96605
Upstream
Published
2026-08-18T15:16:57Z
Modified
2026-09-17T05:36:01Z
Summary
CVE-2026-66046 affecting package expat for versions less than 2.8.3-2
Details

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.

References

Affected packages

Azure Linux:3 / expat

Package

Name
expat
Purl
pkg:rpm/azure-linux/expat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.8.3-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96605.json"