CVE-2026-7210
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
Severity Score
6.3
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r
\r
Fully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
*Credits:
Stan Ulbrych (https://github.com/StanFromIreland), Gregory P. Smith (https://github.com/gpshead)
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2026-04-27 CVE Reserved
- 2026-05-11 CVE Published
- 2026-05-12 CVE Updated
- 2026-05-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-331: Insufficient Entropy
CAPEC
References (5)
| URL | Tag | Source |
|---|---|---|
| https://github.com/python/cpython/issues/149018 | Issue Tracking | |
| http://www.openwall.com/lists/oss-security/2026/05/11/13 |
|
|
| http://www.openwall.com/lists/oss-security/2026/05/11/8 |
|
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|---|---|
| https://github.com/python/cpython/pull/149023 | 2026-05-11 |
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Python Software Foundation Search vendor "Python Software Foundation" | CPython Search vendor "Python Software Foundation" for product "CPython" | < 3.15.0 Search vendor "Python Software Foundation" for product "CPython" and version " < 3.15.0" | en |
Affected
| ||||||
