Medium severity5.9NVD Advisory· Published Aug 20, 2026· Updated Sep 8, 2026
CVE-2026-76956
CVE-2026-76956
Description
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <2.8.4
- osv-coords2 versionspkg:rpm/opensuse/expat&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/expat&distro=openSUSE%20Tumbleweed
< 2.8.4-160000.1.1+ 1 more
- (no CPE)range: < 2.8.4-160000.1.1
- (no CPE)range: < 2.8.4-1.1
Patches
Vulnerability mechanics
References
2- github.com/libexpat/libexpat/pull/1326nvdIssue TrackingPatch
- github.com/libexpat/libexpat/pull/1329nvdIssue TrackingPatch
News mentions
0No linked articles in our index yet.