Bug 2468575 (CVE-2026-45186) - CVE-2026-45186 libexpat: denial of service via crafted XML input
Summary: CVE-2026-45186 libexpat: denial of service via crafted XML input
Keywords:
Status: NEW
Alias: CVE-2026-45186
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2479958 2479960
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-10 07:01 UTC by OSIDB Bzimport
Modified: 2026-07-18 08:29 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:22929 0 None None None 2026-06-03 15:30:12 UTC
Red Hat Product Errata RHBA-2026:22930 0 None None None 2026-06-03 15:38:50 UTC
Red Hat Product Errata RHBA-2026:22931 0 None None None 2026-06-03 15:33:46 UTC
Red Hat Product Errata RHBA-2026:23260 0 None None None 2026-06-04 14:35:47 UTC
Red Hat Product Errata RHBA-2026:24329 0 None None None 2026-06-08 01:10:21 UTC
Red Hat Product Errata RHBA-2026:24378 0 None None None 2026-06-08 10:16:21 UTC
Red Hat Product Errata RHBA-2026:24384 0 None None None 2026-06-08 11:39:58 UTC
Red Hat Product Errata RHBA-2026:24461 0 None None None 2026-06-08 12:44:31 UTC
Red Hat Product Errata RHBA-2026:24501 0 None None None 2026-06-08 14:15:03 UTC
Red Hat Product Errata RHBA-2026:24521 0 None None None 2026-06-08 16:17:23 UTC
Red Hat Product Errata RHBA-2026:24522 0 None None None 2026-06-08 16:17:25 UTC
Red Hat Product Errata RHBA-2026:24523 0 None None None 2026-06-08 16:23:52 UTC
Red Hat Product Errata RHBA-2026:24524 0 None None None 2026-06-08 16:22:13 UTC
Red Hat Product Errata RHBA-2026:24529 0 None None None 2026-06-08 17:02:33 UTC
Red Hat Product Errata RHBA-2026:24763 0 None None None 2026-06-09 12:43:32 UTC
Red Hat Product Errata RHSA-2026:22715 0 None None None 2026-06-03 09:31:42 UTC
Red Hat Product Errata RHSA-2026:22721 0 None None None 2026-06-03 10:36:50 UTC
Red Hat Product Errata RHSA-2026:23230 0 None None None 2026-06-04 13:10:34 UTC
Red Hat Product Errata RHSA-2026:27201 0 None None None 2026-06-22 15:13:39 UTC

Description OSIDB Bzimport 2026-05-10 07:01:10 UTC
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

Comment 3 Thiago Osório 2026-05-27 17:42:05 UTC
Hi, team. I hope you're doing well. 

  Do we have an ETA for the fix for this CVE-2026-45186 vulnerability in RHEL 9 image?

  Regards.

Comment 5 errata-xmlrpc 2026-06-03 09:31:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:22715 https://access.redhat.com/errata/RHSA-2026:22715

Comment 6 errata-xmlrpc 2026-06-03 10:36:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:22721 https://access.redhat.com/errata/RHSA-2026:22721

Comment 7 errata-xmlrpc 2026-06-04 13:10:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:23230 https://access.redhat.com/errata/RHSA-2026:23230

Comment 9 errata-xmlrpc 2026-06-22 15:13:36 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Core Services 2.4.62.SP4

Via RHSA-2026:27201 https://access.redhat.com/errata/RHSA-2026:27201


Note You need to log in before you can comment on or make changes to this bug.