CVE-2026-66046
Description
A flaw was found in the Expat XML parsing library. A remote, unauthenticated attacker can supply a specially crafted XML document to trigger quadratic algorithmic complexity in the storeAtts() function, causing excessive CPU consumption and a denial of service
Statement
An Important severity denial of service vulnerability exists in the Expat library due to inefficient algorithmic complexity when processing XML attributes. Applications parsing untrusted XML are susceptible to remote, unauthenticated attacks where a specially crafted XML payload causes excessive CPU exhaustion, ultimately resulting in service unavailability.
Mitigation
To mitigate, avoid parsing untrusted XML where possible. Where parsing is required, restrict sources using network controls and enforce strict limits on document size, attribute counts, and request rates at the application or proxy level. Additionally, apply strict execution timeouts to cap parser cost and interrupt processes before they can exhaust CPU resources.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.5 | N/A | 7.5 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
The typical consequence is CPU consumption, but memory consumption and consumption of other resources can also occur.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.