!! !! !! If your business relies on Expat beyond January 2027, please consider !! !! funding the maintenance of Expat to ensure its health and security for !! !! you and others. Thank you! !! !! !! !! Sebastian Pipping -- Berlin, 2026-09-22 !! Release 2.8.5 Tue September 22 2026 Security fixes: #1282 CVE-2026-93990 -- Reject high surrogates not followed by a low surrogate during UTF-16 decoding; previously, malformed UTF-16 could be smuggled into the application using Expat and could cause arbitrary damage there, depending on how malformed UTF-16 was handled inside the application; validation was not their job but Expat's. This is similar to past vulnerability CVE-2022-25235. Upstream CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVSS score: 9.8) /////////////////////////////////////////////////////////////////////////////// // The next release will drop two (disabled-by-default) features: // // // // - ATTR_INFO (-DXML_ATTR_INFO, -DEXPAT_ATTR_INFO, --enable-xml-attr-info, // // function XML_GetAttributeInfo, struct XML_AttrInfo) // // - MIN_SIZE (-DXML_MIN_SIZE, -DEXPAT_MIN_SIZE) // // // // If you need them in 2026 and beyond, please share your scenario at // // GitHub issues #1370 (for ATTR_INFO) and/or #1379 (for MIN_SIZE). Thanks! // /////////////////////////////////////////////////////////////////////////////// Bug fixes: #1346 lib: Fix OOM-related memory leak on a failed overflow check #1371 lib: Fix memory alignment for architectures with 128bit pointers like CHERI-RISC-V #1367 xmlwf: Handle errors when closing output files Other changes: #1354 lib: Reject an XML declaration version other than `1.[0-9]+` (which is less strict than XML 1.0r4 (fourth edition) and matches XML 1.0r5 (fifth edition)) #1362 lib: Make Clang, GCC and MSVC warn about use of function XML_SetHashSalt that is deprecated since Expat 2.8.0 #1357 lib: Drop internal macros FASTCALL, PTRCALL, PTRFASTCALL #1367 xmlwf: Document that with `-k` the last error determines the xmlwf exit code in `--help` output #1367 xmlwf: Make exit code 3 documentation match exit code 2 more closely in `--help` output #1352 #1353 CMake|Windows: Refrain from adding `/source-charset:utf-8` for MSVC #1366 #1374 Autotools: Be explicit about the minimum required version of GNU Automake, currently version 1.13 of 2012-12-28 #1351 Autotools|macOS: Sync CMake templates with CMake 4.4.3 #1349 Replace some internal use of XML_Bool with standard bool #1364 tests: Propagate xmltest.sh failures via exit status #1360 tests|xmlwf: Add `#include "expat_config.h"` where missing #1355 tests: Start covering hash table operation #1350 #1369 tests: Drop __cplusplus leftovers #1378 tests: Fix tail pointer when unlinking the last tracked allocation #1376 docs: Emphasize that XML_StopParser is not immediate #1381 docs: Sync XML_FeatureEnum value list in doc/reference.html #1356 #1361 Version info bumped from 13:4:12 (libexpat*.so.1.12.4) to 13:5:12 (libexpat*.so.1.12.5); see https://verbump.de/ for what these numbers do Infrastructure: #1347 Add missing .gitignore entries #1360 CI: Detect missing `#include "expat_config.h"` #1368 CI: Bump MinGW Clang from 23.0.1 to 23.1.1 #1377 CI: Bump Fil-C from 0.684 to 0.685 #1380 CI: Bump Cppcheck from 2.21.0 to 2.22.0 #1372 CI: Extract helper script `apply-htmltidy.sh` #1366 #1374 Autotools: Start to also produce .tar.bz3 release tarballs Special thanks to: Afonso Januário Braian Plaku Florian Schmaus Huang Wenbin Kamila Szewczyk Kartik Kenchi Leo Camus Matthew Fernandez Stan Ulbrych and City of Munich Open Source Sabbatical