CVE-2026-93990

NameCVE-2026-93990
DescriptionExpat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4807-1
Debian Bugs1148665

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
expat (PTS)bookworm2.5.0-1+deb12u2vulnerable
bookworm (security)2.5.0-1+deb12u4fixed
trixie (security), trixie2.8.3-1~deb13u1vulnerable
forky2.8.4-2fixed
sid2.9.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
expatsourcebookworm2.5.0-1+deb12u4DLA-4807-1
expatsource(unstable)2.8.4-21148665

Notes

https://github.com/libexpat/libexpat/pull/1282
Fixed by: https://github.com/libexpat/libexpat/commit/0cfd15bdf4b2c22d6b0df73610709dfb60921091 (R_2_8_5)
Fixed by: https://github.com/libexpat/libexpat/commit/28fcfba540f6933aa8904a1514c4811713d2ab72 (R_2_8_5)

Search for package or bug name: Reporting problems