FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

libexpat -- Improper Handling of Unicode Encoding

Affected packages
expat < 2.8.5

Details

VuXML ID 7fed71c4-be3a-11f1-ab8d-00a0980083d7
Discovery 2026-09-19
Entry 2026-10-04

https://github.com/libexpat/libexpat/pull/1282 reports:

Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.

References

CVE Name CVE-2026-93990
URL https://cveawg.mitre.org/api/cve/CVE-2026-93990