216.73.216.233

CVE-2026-7210

· Published 11/05/2026 18:16 · Modified 12/05/2026 14:20

Labels: CVE-2026-7210 2026-05-11CVE-2026-7210CWE-331[email protected]

Essential information

Published
11/05/2026 18:16
Modified
12/05/2026 14:20
Author
Creator
CVSS
6.3 MEDIUM (v3) 6.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
expat / expat cpe:2.3:a:expat:expat:2.8.0:*:*:*:*:*:*:*

References