CVE-2026-93990
CVE Details
Visit the official vulnerability details page for CVE-2026-93990 to learn more.
Initial Publication
09/19/2026
Last Update
09/28/2026
Third Party Dependency
libexpat
NIST CVE Summary
Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.
CVE Severity
Our Official Summary
Investigation is ongoing to determine how this vulnerability affects our products.
Status
Awaiting Analysis
Affected Products & Versions
| Version | PaletteAI | PaletteAI VerteX |
|---|---|---|
| 1.4.0 | ⚠️ Impacted | ⚠️ Impacted |
| 1.3.2 | ⚠️ Impacted | ⚠️ Impacted |
| 1.2.2 | ⚠️ Impacted | ⚠️ Impacted |
Revision History
No revisions available.