CVE-2026-7210
EUVD-2026-2917811.05.2026, 18:16
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| python | python | 𝑥 < 3.15.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| python | cpython | 𝑥 < 3.13.14 | CNA |
| python | cpython | 3.14.0 ≤ 𝑥 < 3.14.6 | CNA |
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| python3.14 |
| ||
| python3.14-debug |
| ||
| python3.14-debuginfo |
| ||
| python3.14-debugsource |
| ||
| python3.14-devel |
| ||
| python3.14-freethreading |
| ||
| python3.14-freethreading-debug |
| ||
| python3.14-freethreading-devel |
| ||
| python3.14-freethreading-idle |
| ||
| python3.14-freethreading-libs |
| ||
| python3.14-freethreading-test |
| ||
| python3.14-freethreading-tkinter |
| ||
| python3.14-idle |
| ||
| python3.14-libs |
| ||
| python3.14-test |
| ||
| python3.14-tkinter |
|
Common Weakness Enumeration
References