Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91765

Опубликовано: 25 сент. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.

EPSS

Процентиль: 42%
0.00516
Низкий

7.5 High

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 дней назад

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.

CVSS3: 7.5
redhat
8 дней назад

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.

CVSS3: 7.5
msrc
5 дней назад

SOAP: Unbounded Recursion in Server-Side cleanup_xml_node

CVSS3: 7.5
debian
8 дней назад

cleanup_xml_node() in the SOAP XML parser recurses once per XML nestin ...

CVSS3: 7.5
github
9 дней назад

SOAP: Unbounded Recursion in Server-Side cleanup_xml_node

EPSS

Процентиль: 42%
0.00516
Низкий

7.5 High

CVSS3

Дефекты

CWE-674