{"id":"CLSA-2026-1779359157","summary":"Fix CVE(s): CVE-2026-45186","details":"   * SECURITY UPDATE: Denial of service via quadratic attribute-name\n     collision check in libexpat before 2.8.1\n     - debian/patches/CVE-2026-45186.patch: introduce per-element\n       defaultAttsNames hash table and use it for O(1) attribute\n       collision detection in defineAttribute\n     - CVE-2026-45186","modified":"2026-06-04T09:45:28.323177688Z","published":"2026-05-21T10:26:02Z","upstream":["CVE-2026-45186"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779359157.html"}],"affected":[{"package":{"name":"expat","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/expat?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.6-2+deb10u7+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779359157.json"}},{"package":{"name":"libexpat1","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libexpat1?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.6-2+deb10u7+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779359157.json"}},{"package":{"name":"libexpat1-dev","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libexpat1-dev?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.6-2+deb10u7+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779359157.json"}}],"schema_version":"1.7.5"}