CVE-2026-4645Infinite Loop in Azl3 Telegraf 1.31.0-15 ON Azure Linux 3.0

CWE-835Infinite Loop3 documents3 sources
Severity
7.5HIGHOSV
No vector
EPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMar 23

Description

Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions Mariner: Mariner redhat: redhat Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade

🔴Vulnerability Details

1
OSV
CVE-2026-4645: A flaw was found in the `github2026-03-23

📋Vendor Advisories

1
Microsoft
Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions2026-03-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-4645 Impact, Exploitability, and Mitigation Steps | Wiz