Product
The Expat library through version 2.8.4 incorrectly validates UTF-16 surrogate pairs, allowing attackers to perform XML injection via malformed input that obscures markup characters.