CVE-2026-7210

HIGH

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

Title source: cna
STIX 2.1

Description

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Scores

CVSS v3 7.5
EPSS 0.0079
EPSS Percentile 52.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-331
Status published
Products (7)
libexpat_project/libexpat < 2.8.0
python/python 3.15.0 alpha1 (9 CPE variants)
python/python < 3.15.0
Python Software Foundation/CPython < 3.13.14
Python Software Foundation/CPython < 3.15.0
Python Software Foundation/CPython 3.14.0 - 3.14.6
Python Software Foundation/CPython 3.15.0a1 - 3.15.0b2
Published May 11, 2026
Tracked Since May 11, 2026