Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4224

Опубликовано: 16 мар. 2026
Источник: debian
EPSS Низкий

Описание

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.3-4package
python3.13fixed3.13.14-1package
python3.13fixed3.13.5-2+deb13u2trixiepackage
python3.11removedpackage
python3.11fixed3.11.2-6+deb12u8bookwormpackage
python3.9removedpackage
python2.7removedpackage
python2.7end-of-lifebullseyepackage
pypy3not-affectedpackage
pypy3no-dsatrixiepackage
pypy3no-dsabookwormpackage
pypy3postponedbullseyepackage

Примечания

  • https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/

  • https://github.com/python/cpython/issues/145986

  • https://github.com/python/cpython/pull/145987

  • Fixed by: https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768 (main)

  • Fixed by: https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3 (v3.14.4)

  • Fixed by: https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a (v3.13.13)

  • Fixed by: https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785 (3.11 branch)

EPSS

Процентиль: 46%
0.00621
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 5.9
redhat
5 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 7.5
nvd
5 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

msrc
4 месяца назад

Stack overflow parsing XML with deeply nested DTD content models

CVSS3: 7.5
github
5 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

EPSS

Процентиль: 46%
0.00621
Низкий