Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7210

Опубликовано: 11 мая 2026
Источник: redhat
CVSS3: 5.3

Описание

xml.parsers.expat and xml.etree.ElementTree use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

A flaw was found in the python and expat components. Insufficient entropy in the hash-flooding protection mechanism of xml.parsers.expat and xml.etree.ElementTree allows a remote attacker to craft a malicious XML document. This crafted document can trigger a hash flooding attack, leading to a denial of service (DoS) condition.

Отчет

The impact from this flaw is limited to a denial of service in the Python runtime. Host Red Hat systems are not affected in their default configurations.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Red Hat Enterprise Linux 10python3.12Fix deferred
Red Hat Enterprise Linux 10python3.14Fix deferred
Red Hat Enterprise Linux 6pythonFix deferred
Red Hat Enterprise Linux 7pythonFix deferred
Red Hat Enterprise Linux 7python3Fix deferred
Red Hat Enterprise Linux 8python3Fix deferred
Red Hat Enterprise Linux 8python3.12Fix deferred
Red Hat Enterprise Linux 8python36:3.6/python36Fix deferred
Red Hat Enterprise Linux 9python3.12Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-331
https://bugzilla.redhat.com/show_bug.cgi?id=2469216python: expat: Python/Expat: Denial of Service via crafted XML document

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 7.5
nvd
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

msrc
3 месяца назад

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

CVSS3: 7.5
debian
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entro ...

CVSS3: 9.8
github
3 месяца назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

5.3 Medium

CVSS3