{"id":"CVE-2026-93990","published":"2026-09-19T23:17:10.203","lastModified":"2026-09-21T15:17:37.097","description":"Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding markup characters from the parser and enabling XML injection attacks.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwes":["CWE-176"],"vendors":[],"products":[],"references":[{"url":"https://github.com/libexpat/libexpat","tags":[]},{"url":"https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","tags":[]},{"url":"https://github.com/libexpat/libexpat/pull/1282","tags":[]},{"url":"https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate","tags":[]}],"exploitRefs":[{"url":"https://github.com/libexpat/libexpat","tags":[]},{"url":"https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","tags":[]},{"url":"https://github.com/libexpat/libexpat/pull/1282","tags":[]}],"hasPoc":true,"ai":null}