
CVE-2026-45186: libexpat DoS https://www.openwall.com/lists/oss-security/2026/05/11/16 Quadratic runtime from attribute name collision checks allowed DoS through moderately sized crafted XML input. A layer of compression around XML can significantly reduce the minimum attack payload size. Fixed in 2.8.1.
Post summary
A quadratic‑runtime DoS vulnerability in libexpat (CVE‑2026‑45186) allows attackers to craft XML with attribute name collisions; the fix is available in version 2.8.1 and technical details on payload sizing are provided.




