← Back

CVE-2026-7210

nvd nist
Published: May 11, 2026Modified: Aug 14, 2026

JSON object

Loading...
6.3
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: CNA (Secondary)

Description

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Affected (11)

Products: Python: Python
1 product
Python
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Python
Before 3.13.14
From 3.14.0 to 3.14.6
Version 3.15.0 alpha1
Version 3.15.0 alpha2
Version 3.15.0 alpha3
Version 3.15.0 alpha4
Version 3.15.0 alpha5
Version 3.15.0 alpha6
Version 3.15.0 alpha7
Version 3.15.0 alpha8
Version 3.15.0 beta1

Timeline

No history available yet.