Update expat to version 2.8.1 (MINDBREEZE42693)

ID: MINDBREEZE42693 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 7.5 High 
Status: Final 
First published: August 5, 2026 
CVEs: CVE-2026-41080, CVE-2026-45186 

Summary 

  • libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. 
  • In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. 

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 26.4 Release
  • Mindbreeze InSpire SaaS 26.4 Release