Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks. | Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds. |
| Title | Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate | Expat before 2.8.5 Malformed UTF-16 Acceptance via Unchecked Surrogate |
| References |
|
Wed, 23 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-91 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 21 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libexpat
Libexpat expat |
|
| Vendors & Products |
Libexpat
Libexpat expat |
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks. | |
| Title | Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate | |
| First Time appeared |
Libexpat Project
Libexpat Project libexpat |
|
| Weaknesses | CWE-176 | |
| CPEs | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libexpat Project
Libexpat Project libexpat |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T16:11:06.770Z
Reserved: 2026-09-19T10:55:49.093Z
Link: CVE-2026-93990
Updated: 2026-09-21T15:11:05.367Z
Status : Awaiting Analysis
Published: 2026-09-19T23:17:10.203
Modified: 2026-09-28T17:17:53.037
Link: CVE-2026-93990
OpenCVE Enrichment
Updated: 2026-09-28T18:15:04Z