Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2026-7210

HIGH 7.5

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Attack vector : Network No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS 0.79% above median percentile 52.9%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Python 3.12 Windows winget:Python.Python.3.12
    Affected Fixed in Latest tracked 3.12.10 undetermined
Vulnerable CPE configurations (11)
Vendor Product Versions
python python
All platforms (wildcard)
<3.13.14
python python
All platforms (wildcard)
≥3.14.0 <3.14.6
python python
All platforms (wildcard)
python python
All platforms (wildcard)
python python
All platforms (wildcard)
python python
All platforms (wildcard)
python python
All platforms (wildcard)
python python
All platforms (wildcard)
python python
All platforms (wildcard)
python python
All platforms (wildcard)
python python
All platforms (wildcard)
View on NVD ↗ Advisory · github.com