Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-32287

Опубликовано: 26 мар. 2026
Источник: debian
EPSS Низкий

Описание

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-antchfx-xpathfixed1.3.6-1package
golang-github-antchfx-xpathno-dsatrixiepackage
golang-github-antchfx-xpathno-dsabookwormpackage
golang-github-antchfx-xpathpostponedbullseyepackage

Примечания

  • https://github.com/antchfx/xpath/issues/121

  • Fixed by: https://github.com/antchfx/xpath/commit/afd4762cc342af56345a3fb4002a59281fcab494 (v1.3.6)

EPSS

Процентиль: 41%
0.00519
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

CVSS3: 6.2
redhat
4 месяца назад

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

CVSS3: 7.5
nvd
4 месяца назад

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

msrc
4 месяца назад

Infinite loop in github.com/antchfx/xpath

CVSS3: 7.5
github
4 месяца назад

XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion

EPSS

Процентиль: 41%
0.00519
Низкий