Junglewise Threat Intelligence

CVE-2026-23822: HPE Aruba AOS-8 XML entity expansion in DHCP services

CVE-2026-23822 · Severity: medium · CVSS 5.3 · Published 2026-05-12

Technologies: HPE Aruba Networking AOS-8 Instant. Vendors: HPE Aruba Networking.

Executive brief

A vulnerability exists in the DHCP services of HPE Aruba Networking Access Points running AOS-8 Instant software. An unauthenticated attacker could exploit this flaw to cause the device to consume excessive resources, leading to a service outage or reduced network availability. This disruption requires some level of user interaction to be triggered and specifically impacts the wireless connectivity provided by these access points.

Technical details

The vulnerability is classified as an Improper Restriction of Recursive Entity References in DTDs (CWE-776), commonly known as an XML Entity Expansion or 'Billion Laughs' attack. It resides within the XML handling component of the DHCP services in AOS-8 Instant firmware. An unauthenticated remote attacker can exploit this by sending specially crafted XML data that, when processed, causes excessive CPU and memory consumption. The attack requires a high complexity (AC:H) and user interaction (UI:R) to succeed. Successful exploitation results in a Denial of Service (DoS) affecting the availability of the Access Point.

Affected products

  • HPE Aruba Networking AOS-8 Instant 8.x.x.x

Timeline

  • 2026-05-12: disclosed: Initial publication of the vulnerability advisory.

References

Related threats