Fedora Account System
Red Hat Associate
Red Hat Customer
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:72448 https://access.redhat.com/errata/RHSA-2026:72448
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:72663 https://access.redhat.com/errata/RHSA-2026:72663
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:74001 https://access.redhat.com/errata/RHSA-2026:74001