CVE-2026-7210CRITICAL 7.5EPSS p51.5%
CVE-2026-7210CVE-2026-7210
python / python
Description
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
Scoring
| CVSS 3.1 | 7.5 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.79% probability of exploitation · percentile 51.5% · 2026-06-19T12:03:05Z |
| Published | 2026-05-11 |
| Last modified | 2026-06-15 |
Underlying weaknesses· 1
References
- https://github.com/python/cpython/issues/149018
- https://github.com/python/cpython/pull/149023
- https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/
- http://www.openwall.com/lists/oss-security/2026/05/11/13
- http://www.openwall.com/lists/oss-security/2026/05/11/8
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Insufficient Entropycwe-331 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.