CVE-2026-93990
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
19/09/2026
Last modified:
28/09/2026
Description
Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://blog.hartwork.org/posts/expat-2-8-5-released/
- https://github.com/libexpat/libexpat
- https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a
- https://github.com/libexpat/libexpat/pull/1282
- https://github.com/libexpat/libexpat/releases/tag/R_2_8_5
- https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate


