Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-7210

Опубликовано: 11 мая 2026
Источник: debian
EPSS Низкий

Описание

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.6-1package
python3.13fixed3.13.14-1package
python3.13no-dsatrixiepackage
python3.11removedpackage
python3.11no-dsabookwormpackage
python3.9removedpackage
python3.9postponedbullseyepackage
python2.7removedpackage
python2.7end-of-lifebullseyepackage

Примечания

  • https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/

  • https://github.com/python/cpython/issues/149018

  • https://github.com/python/cpython/pull/149023

  • https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4 (main)

  • https://github.com/python/cpython/pull/149645 (3.15)

  • https://github.com/python/cpython/pull/149646 (3.14)

  • Fully mitigating this vulnerability requires fixing both libexpat

  • (CVE-2026-41080) and applying the python patch for CVE-2026-7210.

EPSS

Процентиль: 52%
0.0079
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 5.3
redhat
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 7.5
nvd
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

msrc
3 месяца назад

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

CVSS3: 9.8
github
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

EPSS

Процентиль: 52%
0.0079
Низкий