
CVE-2026-72522 libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing i… https://www.cve.org/CVERecord?id=CVE-2026-72522
Post summary
The note announces CVE-2026-72522, detailing an out‑of‑bounds read and infinite loop flaw in libexpat caused by surrogate handling.
