CVE-2026-41080
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVSS
2.9
Low
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Apr 16, 2026 · Last modified: Jul 14, 2026 · CWE-331
0.4%EPSS · 30 days0.4%
2026-08-252026-09-22
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
- blog.hartwork.orghttps://blog.hartwork.org/posts/expat-2-8-0-released/
- github.comhttps://github.com/libexpat/libexpat/issues/47
- github.comhttps://github.com/libexpat/libexpat/pull/1183
- www.openwall.comhttps://www.openwall.com/lists/oss-security/2026/04/26/1
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/04/26/1
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/html/ssa-082556.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-136399.8 CRI42.2%
——13An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.4dCVE-2026-905628.1 HIG36.3%
——11LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.7dCVE-2026-801714.7 MED0.4%
——0Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.13dCVE-2026-626467.4 HIG24.6%
——7A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.12dCVE-2026-274907.5 HIG24.6%
——7Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.13dCVE-2026-49375.3 MED0.9%
——0IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.28d