Bug 2468575 (CVE-2026-45186)

Summary: CVE-2026-45186 libexpat: denial of service via crafted XML input
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: csutherl, gtanzill, jbuscemi, jclere, jmitchel, kshier, pjindal, plodge, rhel-process-autobot, stcannon, szappis, teagle, tosorio, vchlup, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in libexpat. When processing a specially crafted XML input containing a specific pattern of attributes, the parsing time increases quadratically due to checks for attribute name collisions. This consumes excessive CPU resources and eventually results in a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2479958, 2479960    
Bug Blocks:    

Description OSIDB Bzimport 2026-05-10 07:01:10 UTC
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

Comment 3 Thiago Osório 2026-05-27 17:42:05 UTC
Hi, team. I hope you're doing well. 

  Do we have an ETA for the fix for this CVE-2026-45186 vulnerability in RHEL 9 image?

  Regards.

Comment 5 errata-xmlrpc 2026-06-03 09:31:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:22715 https://access.redhat.com/errata/RHSA-2026:22715

Comment 6 errata-xmlrpc 2026-06-03 10:36:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:22721 https://access.redhat.com/errata/RHSA-2026:22721

Comment 7 errata-xmlrpc 2026-06-04 13:10:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:23230 https://access.redhat.com/errata/RHSA-2026:23230

Comment 9 errata-xmlrpc 2026-06-22 15:13:36 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Core Services 2.4.62.SP4

Via RHSA-2026:27201 https://access.redhat.com/errata/RHSA-2026:27201