Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4224

Опубликовано: 16 мар. 2026
Источник: debian
EPSS Низкий

Описание

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14unfixedpackage
python3.13unfixedpackage
python3.11removedpackage
python3.9removedpackage
python2.7removedpackage
python2.7end-of-lifebullseyepackage
pypy3unfixedpackage
pypy3no-dsatrixiepackage
pypy3no-dsabookwormpackage

Примечания

  • https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/

  • https://github.com/python/cpython/issues/145986

  • https://github.com/python/cpython/pull/145987

  • Fixed by: https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768 (main)

  • Fixed by: https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3 (3.14)

  • Fixed by: https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a (3.13)

EPSS

Процентиль: 5%
0.00019
Низкий

Связанные уязвимости

ubuntu
9 дней назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 5.9
redhat
9 дней назад

A stack overflow flaw has been discovered in the python pyexpat module. When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. This will result in a program crash.

nvd
9 дней назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

msrc
7 дней назад

Stack overflow parsing XML with deeply nested DTD content models

github
9 дней назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

EPSS

Процентиль: 5%
0.00019
Низкий