A vulnerability categorized as critical has been discovered in Libexpat up to 2.8.2. This affects the function *_toUtf16 of the component Unicode Handler. Such manipulation leads to out-of-bounds read.

This vulnerability is referenced as CVE-2026-72522. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.