Expat 2.8.4 XML Parser UTF-16 Surrogate Validation Flaw (CVE-2026-93990)
CVE-2026-93990 Published on September 19, 2026

Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.

NVD

Vulnerability Analysis

CVE-2026-93990 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

Improper Handling of Unicode Encoding

The software does not properly handle when an input contains Unicode encoding.


Products Associated with CVE-2026-93990

Want to know whenever a new CVE is published for Libexpatproject Libexpat? stack.watch will email you.

 

Affected Versions

libexpat: