CVE-2026-76956CWE-394
CVE-2026-76956
Medium · published August 20, 2026
What it is
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
The record
Technical detail
- CVSS v3.1
- 5.9 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00278 · 20.0th percentile
- Weakness
- CWE-394 · Unexpected Status Code or Return Value
- Published
- 2026-08-20T09:16Z
References (2)
EPSS history
Timeline