CVE-2026-72522: libexpat Vulnerability Allows Denial of Service
A medium-severity vulnerability (CVE-2026-72522) in libexpat before version 2.8.3 can lead to a denial-of-service (DoS) attack due to an out-of-bounds read and infinite loop during Unicode processing. This vulnerability has a CVSS score of 6.2 and is not currently being actively exploited. Affected products include libexpat versions prior to 2.8.3.