CVE-2026-7210
MEDIUM
6,3
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
331
Insufficient Entropy
DraftCommon Consequences
Security Scopes Affected:
Access Control
Other
Potential Impacts:
Bypass Protection Mechanism
Other
Applicable Platforms
All platforms may be affected
http://www.openwall.com/lists/oss-security/2026/05/11/8
https://github.com/python/cpython/issues/149018
https://github.com/python/cpython/pull/149023
https://mail.python.org/archives/list/[email protected]/thread/PNY5O…