RHSA-2026:11004LowCVSS 3.7

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
April 27, 2026
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-41080 — libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML

🎯 Affected products4

  • Red Hat Hardened Images
  • expat-main@aarch64 as a component of Red Hat Hardened Images
  • expat-main@src as a component of Red Hat Hardened Images
  • expat-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Applications that process untrusted XML documents using libexpat should implement robust input validation to filter out malicious XML structures. Restricting access to services that process untrusted XML can also reduce the attack surface. If a service is affected, restarting it may be required after implementing input validation or access restrictions.

🔗 References (5)