CVE-2026-7210
published 2026-05-11CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.79%
52.1th percentile
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python3.14 | — | — |
| debian | python3.9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| python | python | < 3.15.0 | 3.15.0 |
| python | python | — | — |
| python36_3.6 | python36 | — | — |
| python_software_foundation | cpython | < 3.13.14 | 3.13.14 |
| python_software_foundation | cpython | >= 3.14.0 < 3.14.6 | 3.14.6 |
| python_software_foundation | cpython | >= 3.15.0a1 < 3.15.0b2 | 3.15.0b2 |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gaudi-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| ubuntu | python2.7 | — | — |
| ubuntu | python3.5 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Python CPython up to 3.14.x XML xml.parsers.Expat/xml.etree.ElementTree entropy (ID 149018)
vuldb·2026-05-11·CVSS 6.3
CVE-2026-7210 [MEDIUM] Python CPython up to 3.14.x XML xml.parsers.Expat/xml.etree.ElementTree entropy (ID 149018)
A vulnerability, which was classified as problematic, has been found in Python CPython up to 3.14.x. The impacted element is the function xml.parsers.Expat/xml.etree.ElementTree of the component XML Handler. The manipulation leads to insufficient entropy.
This vulnerability is traded as CVE-2026-7210. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-wxv8-w48j-r2f4: `xml
ghsa_unreviewed·2026-05-11
CVE-2026-7210 [MEDIUM] CWE-331 GHSA-wxv8-w48j-r2f4: `xml
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
Ubuntu
Python vulnerability
vendor_ubuntu·2026-07-09
CVE-2026-7210 Python vulnerability
Title: Python vulnerability
Summary: Python could be made to crash if it received specially crafted
input.
It was discovered that Python did not use sufficient entropy for Expat
hash-flooding protection in the xml.parsers.expat and xml.etree.ElementTree
modules. An attacker could use this to cause a denial of service via a
crafted XML document.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python: expat: Python/Expat: Denial of Service via crafted XML document
vendor_redhat·2026-05-11·CVSS 6.3
CVE-2026-7210 [MEDIUM] CWE-331 python: expat: Python/Expat: Denial of Service via crafted XML document
python: expat: Python/Expat: Denial of Service via crafted XML document
A flaw was found in the `python` and `expat` components. Insufficient entropy in the hash-flooding protection mechanism of `xml.parsers.expat` and `xml.etree.ElementTree` allows a remote attacker to craft a malicious XML document. This crafted document can trigger a hash flooding attack, leading to a denial of service (DoS) condition.
Statement: The impact from this flaw is limited to a denial of service in the Python runtime. Host Red Hat systems are not affected in their default configurations.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installat
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-7210 asahi-installer: Python/Expat: Denial of Service via crafted XML document [fedora-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 asahi-installer: Python/Expat: Denial of Service via crafted XML document [fedora-all]
CVE-2026-7210 asahi-installer: Python/Expat: Denial of Service via crafted XML document [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 python3.15: Python/Expat: Denial of Service via crafted XML document [fedora-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 python3.15: Python/Expat: Denial of Service via crafted XML document [fedora-all]
CVE-2026-7210 python3.15: Python/Expat: Denial of Service via crafted XML document [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 python3.10: Python/Expat: Denial of Service via crafted XML document [fedora-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 python3.10: Python/Expat: Denial of Service via crafted XML document [fedora-all]
CVE-2026-7210 python3.10: Python/Expat: Denial of Service via crafted XML document [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 python3.6: Python/Expat: Denial of Service via crafted XML document [fedora-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 python3.6: Python/Expat: Denial of Service via crafted XML document [fedora-all]
CVE-2026-7210 python3.6: Python/Expat: Denial of Service via crafted XML document [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 python3.13: Python/Expat: Denial of Service via crafted XML document [fedora-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 python3.13: Python/Expat: Denial of Service via crafted XML document [fedora-all]
CVE-2026-7210 python3.13: Python/Expat: Denial of Service via crafted XML document [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 python3.13: Python/Expat: Denial of Service via crafted XML document [epel-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 python3.13: Python/Expat: Denial of Service via crafted XML document [epel-all]
CVE-2026-7210 python3.13: Python/Expat: Denial of Service via crafted XML document [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 python3.14: Python/Expat: Denial of Service via crafted XML document [fedora-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 python3.14: Python/Expat: Denial of Service via crafted XML document [fedora-all]
CVE-2026-7210 python3.14: Python/Expat: Denial of Service via crafted XML document [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 asahi-installer: Python/Expat: Denial of Service via crafted XML document [epel-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 asahi-installer: Python/Expat: Denial of Service via crafted XML document [epel-all]
CVE-2026-7210 asahi-installer: Python/Expat: Denial of Service via crafted XML document [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 mingw-python3: Python/Expat: Denial of Service via crafted XML document [fedora-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 mingw-python3: Python/Expat: Denial of Service via crafted XML document [fedora-all]
CVE-2026-7210 mingw-python3: Python/Expat: Denial of Service via crafted XML document [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 python3.12: Python/Expat: Denial of Service via crafted XML document [fedora-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 python3.12: Python/Expat: Denial of Service via crafted XML document [fedora-all]
CVE-2026-7210 python3.12: Python/Expat: Denial of Service via crafted XML document [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 python3.9: Python/Expat: Denial of Service via crafted XML document [fedora-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 python3.9: Python/Expat: Denial of Service via crafted XML document [fedora-all]
CVE-2026-7210 python3.9: Python/Expat: Denial of Service via crafted XML document [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 python3.11: Python/Expat: Denial of Service via crafted XML document [fedora-all]
bugzilla·2026-06-02·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 python3.11: Python/Expat: Denial of Service via crafted XML document [fedora-all]
CVE-2026-7210 python3.11: Python/Expat: Denial of Service via crafted XML document [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7210 python: expat: Python/Expat: Denial of Service via crafted XML document
bugzilla·2026-05-11·CVSS 6.3
CVE-2026-7210 [MEDIUM] CVE-2026-7210 python: expat: Python/Expat: Denial of Service via crafted XML document
CVE-2026-7210 python: expat: Python/Expat: Denial of Service via crafted XML document
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27ahttps://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145fhttps://github.com/python/cpython/issues/149018https://github.com/python/cpython/pull/149023https://mail.python.org/archives/list/[email protected]/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/http://www.openwall.com/lists/oss-security/2026/05/11/13http://www.openwall.com/lists/oss-security/2026/05/11/8
2026-05-11
Published