- Sources: primary
- Summary: Maintainer Sebastian Pipping released Expat 2.8.5 on 2026-09-22, fixing CVE-2026-93990, where versions before 2.8.5 did not validate that the second half of a surrogate pair falls in the low-surrogate range 0xDC00 to 0xDFFF. An attacker could therefore smuggle malformed UTF-16 into the calling application, where the damage depends on how that application handles it. Kartik Kenchi reported and fixed the flaw, and no exploitation is reported.
- Why it matters: libexpat is one of the two most widely used C XML parsers and is bundled or pinned in a very large number of downstream projects, so the maintainer's request reaches packagers and anyone carrying a bundled or pinned copy, not only direct dependents.
send feedback on this story