boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-93990

libexpat libexpat — Expat before 2.8.5 Malformed UTF-16 Acceptance via Unchecked Surrogate
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   H   N    8.7   .0040   32.2     —
AFFECTED
  Product   Versions     Fixed
  libexpat  unspecified  2.8.5
TIMELINE
  Sep 19  Reserved by VulnCheck
  Sep 19  Published (CNA: VulnCheck)
  Sep 28  PATCH SHIPPED — CVE-2026-93990 (libexpat). Fixed in libexpat 2.8.5.
CWE-176 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Awaiting Analysis

Description

Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 19, 2026ReservedReserved by VulnCheck
September 19, 2026PublishedPublished (CNA: VulnCheck)
September 28, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-93990 (libexpat). Fixed in libexpat 2.8.5.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
libexpatlibexpat——2.8.5

Weaknesses

CWE-176

References (6)

Related

Authoritative record: CVE-2026-93990 at cve.org

Vendors: libexpat

Weaknesses: CWE-176

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-93990 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.