CVSS
6.2
CVSS v3.1
EPSS
0.2%
Exploit Prediction Score
Published
August 10, 2026
Exploitability
EPSS probability 0.2%
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).