CVE-2026-4224
published 2026-03-16CVE-2026-4224: When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.62%
45.8th percentile
When an Expat parser with a registered ElementDeclHandler parses an inline
document type definition containing a deeply nested content model a C stack
overflow occurs.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pypy3 | < python3.14 3.14.3-4 (sid) | python3.14 3.14.3-4 (sid) |
| debian | python2.7 | < python3.14 3.14.3-4 (sid) | python3.14 3.14.3-4 (sid) |
| debian | python3.11 | < python3.14 3.14.3-4 (sid) | python3.14 3.14.3-4 (sid) |
| debian | python3.13 | < python3.14 3.14.3-4 (sid) | python3.14 3.14.3-4 (sid) |
| debian | python3.14 | < python3.14 3.14.3-4 (sid) | python3.14 3.14.3-4 (sid) |
| debian | python3.9 | < python3.14 3.14.3-4 (sid) | python3.14 3.14.3-4 (sid) |
| msrc | azl3_python3_3.12.9-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_python3_3.9.19-19_on_cbl_mariner_2.0 | — | — |
| python | python | < 3.10.0 | 3.10.0 |
| python | python | — | — |
| python | python | >= 3.13.0 < 3.13.13 | 3.13.13 |
| python | python | >= 3.14.0 < 3.14.4 | 3.14.4 |
| python_software_foundation | cpython | < 3.13.13 | 3.13.13 |
| python_software_foundation | cpython | >= 3.14.0 < 3.14.4 | 3.14.4 |
| python_software_foundation | cpython | >= 3.15.0a1 < 3.15.0a8 | 3.15.0a8 |
| ubuntu | python3.10 | — | — |
| ubuntu | python3.12 | — | — |
| ubuntu | python3.14 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.0MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_msrc6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 3.3
CVE-2026-9669 [LOW] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly normalized paths in the tarfile
module. An attacker could possibly use this issue to bypass path
restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2025-13462)
It was discovered that Python's HTMLParser incorrectly handled certain
malformed HTML input. An attacker could possibly use this issue to cause
Python to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534)
It was discovered that Python's email module incorrectly quoted newlines
in headers. An attacker could possibly use this issue to inject arbitrary
email headers. This issue only affected Ubuntu 22.04 L
Red Hat
cpython: Stack overflow parsing XML with deeply nested DTD content models
vendor_redhat·2026-03-16·CVSS 6.0
CVE-2026-4224 [MEDIUM] CWE-805 cpython: Stack overflow parsing XML with deeply nested DTD content models
cpython: Stack overflow parsing XML with deeply nested DTD content models
When an Expat parser with a registered ElementDeclHandler parses an inline
document type definition containing a deeply nested content model a C stack
overflow occurs.
A stack overflow flaw has been discovered in the python pyexpat module. When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. This will result in a program crash.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: python3.12 (Red Hat En
Microsoft
Stack overflow parsing XML with deeply nested DTD content models
vendor_msrc·2026-03-10·CVSS 6.0
CVE-2026-4224 [MEDIUM] Stack overflow parsing XML with deeply nested DTD content models
Stack overflow parsing XML with deeply nested DTD content models
Mariner: Mariner
PSF: PSF
Customer Action Required: Yes
Debian
CVE-2026-4224: pypy3 - When an Expat parser with a registered ElementDeclHandler parses an inline docum...
vendor_debian·2026·CVSS 6.0
CVE-2026-4224 [MEDIUM] CVE-2026-4224: pypy3 - When an Expat parser with a registered ElementDeclHandler parses an inline docum...
When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
VulDB
Python CPython up to 3.14.x Expat Parser ElementDeclHandler stack-based overflow (EUVD-2026-12486 / Nessus ID 302535)
vuldb·2026-04-24·CVSS 6.0
CVE-2026-4224 [MEDIUM] Python CPython up to 3.14.x Expat Parser ElementDeclHandler stack-based overflow (EUVD-2026-12486 / Nessus ID 302535)
A vulnerability categorized as critical has been discovered in Python CPython up to 3.14.x. This vulnerability affects the function ElementDeclHandler of the component Expat Parser. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability is registered as CVE-2026-4224. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-h46w-ffvp-4pw5: When an Expat parser with a registered ElementDeclHandler parses an inline
document type definition containing a deeply nested content model a C stack
ghsa_unreviewed·2026-03-16
CVE-2026-4224 [MEDIUM] CWE-674 GHSA-h46w-ffvp-4pw5: When an Expat parser with a registered ElementDeclHandler parses an inline
document type definition containing a deeply nested content model a C stack
When an Expat parser with a registered ElementDeclHandler parses an inline
document type definition containing a deeply nested content model a C stack
overflow occurs.
OSV
CVE-2026-4224: When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack
osv·2026-03-16·CVSS 6.0
CVE-2026-4224 [MEDIUM] CVE-2026-4224: When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack
When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-12781 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2025-12781 [MEDIUM] CVE-2025-12781 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12781 :
Python Interpreter vulnerability analysis and mitigation
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.
This behavior can only be insecure if your application uses an alternate base64 alphabet (without "+/"). If your application does not use the "altchars" parameter or
Wiz
CVE-2025-13462 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2025-13462 [LOW] CVE-2025-13462 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13462 :
Python Interpreter vulnerability analysis and mitigation
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
Source : NVD
## 2
Score
Published March 12, 2026
Severity LOW
CNA Score 2.0
Affected Technologies
Python Interpreter
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python3.14
cpe:2.3:a:python:python
Sources
NVD
Debian 11,
Wiz
CVE-2026-3479 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2026-3479 [LOW] CVE-2026-3479 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3479 :
Python Interpreter vulnerability analysis and mitigation
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Source : NVD
## 2.1
Score
Published March 18, 2026
Severity LOW
CNA Score 2.1
Affected Technologies
Python Interpreter
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python3.14
python3-devel
Sources
NVD
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 20, 2026
Debian 14 No Fix Added at: Mar 20, 2026
Echo Has Fix Added at: Mar 20, 2026
Red Hat 6, 7, 8, 9, 10 Severity LOW No Fix Added at: Mar 20, 2026
Debian Has F
Wiz
CVE-2025-15282 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2025-15282 [LOW] CVE-2025-15282 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15282 :
Python Interpreter vulnerability analysis and mitigation
User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.
Source : NVD
## 6
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libpython3_13t1_0
python313-curses
Sources
NVD
Chainguard Has Fix Added at: Jan 28, 2026
Debian 11 Severity MEDIUM Has Fix Added at: Jan 23, 2026
Debian 12, 13 Severity MEDIUM No Fix Added at: Jan 23, 2026
Debian 14 Has Fix Ad
Wiz
CVE-2026-4519 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2026-4519 [MEDIUM] CVE-2026-4519 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4519 :
Python Interpreter vulnerability analysis and mitigation
The webbrowser.open() API would accept leading dashes in the URL which
could be handled as command line options for certain web browsers. New
behavior rejects leading dashes. Users are recommended to sanitize URLs
prior to passing to webbrowser.open().
Source : NVD
## 7
Score
Published March 20, 2026
Severity HIGH
CNA Score 7.0
Affected Technologies
Python Interpreter
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python39-devel:3.9::python3x-setuptools
python3.13
Sources
NVD
AlmaLinux 8 Severity HIGH Has Fix Added at: A
Wiz
CVE-2025-11468 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.7
CVE-2025-11468 [MEDIUM] CVE-2025-11468 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-11468 :
Python Interpreter vulnerability analysis and mitigation
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.
Source : NVD
## 5.7
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.7
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python39-devel:3.9::python39-toml
python39-devel:3.9::python-idna
Sources
NVD
CBL-Mariner 3.0 Severity MEDIUM
Wiz
CVE-2026-0672 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2026-0672 [MEDIUM] CVE-2026-0672 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0672 :
Python Interpreter vulnerability analysis and mitigation
When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.
Source : NVD
## 6
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 36.6
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
python3.10-tkinter
python311-devel
Sources
NVD
CBL-Mariner 2.0 Severity MEDIUM Has Fix Added at: Feb 08, 2026
CBL-Mariner 3.0 Severity MEDIUM Has Fix Add
Wiz
CVE-2026-2297 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2026-2297 [LOW] CVE-2026-2297 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2297 :
Python Interpreter vulnerability analysis and mitigation
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.
Source : NVD
## 5.7
Score
Published March 4, 2026
Severity MEDIUM
CNA Score 5.7
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python39-devel:3.9::python39-psycopg2-tests
python39-devel:3.9::python-wheel
Sources
NVD
Chainguard Has Fix
Wiz
CVE-2026-4224 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2026-4224 [LOW] CVE-2026-4224 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4224 :
Python Interpreter vulnerability analysis and mitigation
When an Expat parser with a registered ElementDeclHandler parses an inline
document type definition containing a deeply nested content model a C stack
overflow occurs.
Source : NVD
## 6
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python-3.14
python36:3.6::python3-distro
Sources
NVD
Chainguard Has Fix Added at: Apr 05, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 No Fix Added at: Mar 17,
Wiz
CVE-2026-3644 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2026-3644 [LOW] CVE-2026-3644 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3644 :
Python Interpreter vulnerability analysis and mitigation
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
Source : NVD
## 6
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 29.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python3.11-debug
python39-devel:3.9::m
Bugzilla
CVE-2026-4224 python3.15: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
bugzilla·2026-03-16·CVSS 6.0
CVE-2026-4224 [MEDIUM] CVE-2026-4224 python3.15: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
CVE-2026-4224 python3.15: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-d494efe6a9 (python3.15-3.15.0~a8-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-d494efe6a9
---
FEDORA-2026-7ea30e843c (python3.15-3.15.0~a8-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-7ea30e843c
---
FEDORA-2026-485183030a (python3.15-3.15.0~a8-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedorapr
Bugzilla
CVE-2026-4224 python3.11: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
bugzilla·2026-03-16·CVSS 6.0
CVE-2026-4224 [MEDIUM] CVE-2026-4224 python3.11: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
CVE-2026-4224 python3.11: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
PRs:
https://src.fedoraproject.org/rpms/python3.11/pull-request/229
https://src.fedoraproject.org/rpms/python3.11/pull-request/230
https://src.fedoraproject.org/rpms/python3.11/pull-request/231
https://src.fedoraproject.org/rpms/python3.11/pull-request/232
---
FEDORA-2026-a5ba8297fd (python3.11-3.11.15-4.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-a5ba8297fd
---
FEDORA-2026-a5ba8297fd (pyth
Bugzilla
CVE-2026-4224 python3.12: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
bugzilla·2026-03-16·CVSS 6.0
CVE-2026-4224 [MEDIUM] CVE-2026-4224 python3.12: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
CVE-2026-4224 python3.12: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
PRs:
https://src.fedoraproject.org/rpms/python3.12/pull-request/221
https://src.fedoraproject.org/rpms/python3.12/pull-request/222
https://src.fedoraproject.org/rpms/python3.12/pull-request/223
https://src.fedoraproject.org/rpms/python3.12/pull-request/224
---
FEDORA-2026-2dfcf9d705 (python3.12-3.12.13-3.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-2dfcf9d705
---
FEDORA-2026-2dfcf9d705 (pyth
Bugzilla
CVE-2026-4224 cpython: Stack overflow parsing XML with deeply nested DTD content models
bugzilla·2026-03-16·CVSS 6.0
CVE-2026-4224 [MEDIUM] CVE-2026-4224 cpython: Stack overflow parsing XML with deeply nested DTD content models
CVE-2026-4224 cpython: Stack overflow parsing XML with deeply nested DTD content models
When an Expat parser with a registered ElementDeclHandler parses an inline
document type definition containing a deeply nested content model a C stack
overflow occurs.
Bugzilla
CVE-2026-4224 python3.13: Stack overflow parsing XML with deeply nested DTD content models [epel-all]
bugzilla·2026-03-16·CVSS 6.0
CVE-2026-4224 [MEDIUM] CVE-2026-4224 python3.13: Stack overflow parsing XML with deeply nested DTD content models [epel-all]
CVE-2026-4224 python3.13: Stack overflow parsing XML with deeply nested DTD content models [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This has been fixed upstream in 3.13.13, and we have that version in all EPELs.
Bugzilla
CVE-2026-4224 python3.13: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
bugzilla·2026-03-16·CVSS 6.0
CVE-2026-4224 [MEDIUM] CVE-2026-4224 python3.13: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
CVE-2026-4224 python3.13: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-80165205dc (python3.13-3.13.13-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-80165205dc
---
FEDORA-2026-13c6899032 (python3.13-3.13.13-1.fc42 and python3-docs-3.13.13-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-13c6899032
Bugzilla
CVE-2026-4224 mingw-python3: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
bugzilla·2026-03-16·CVSS 6.0
CVE-2026-4224 [MEDIUM] CVE-2026-4224 mingw-python3: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
CVE-2026-4224 mingw-python3: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-ff5da930eb (mingw-python3-3.11.15-2.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-ff5da930eb
---
FEDORA-2026-22d8c9f967 (mingw-python3-3.11.15-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-22d8c9f967
---
FEDORA-2026-3d13d52f58 (mingw-python3-3.11.15-2.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fe
Bugzilla
CVE-2026-4224 python3.14: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
bugzilla·2026-03-16·CVSS 6.0
CVE-2026-4224 [MEDIUM] CVE-2026-4224 python3.14: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
CVE-2026-4224 python3.14: Stack overflow parsing XML with deeply nested DTD content models [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-884eccdb03 (python3.14-3.14.4-1.fc44 and python3-docs-3.14.4-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-884eccdb03
---
FEDORA-2026-9a8fddee0b (python3.14-3.14.4-1.fc43 and python3-docs-3.14.4-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-9a8fddee0b
https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4ahttps://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914feehttps://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768https://github.com/python/cpython/issues/145986https://github.com/python/cpython/pull/145987https://mail.python.org/archives/list/[email protected]/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/http://www.openwall.com/lists/oss-security/2026/03/16/4
2026-03-16
Published