CVE-2026-45186 In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. Information published. EPSS 0.00 CVE-2026-45186 libexpat US Microsoft Security · 11. 5. 10:03