Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxv8-w48j-r2f4

Опубликовано: 11 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 9.8

Описание

xml.parsers.expat and xml.etree.ElementTree use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

xml.parsers.expat and xml.etree.ElementTree use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

EPSS

Процентиль: 52%
0.0079
Низкий

6.3 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 5.3
redhat
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 7.5
nvd
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

msrc
3 месяца назад

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

CVSS3: 7.5
debian
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entro ...

EPSS

Процентиль: 52%
0.0079
Низкий

6.3 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-331