CVE-2026-7210
Beschrijving NL
`xml.parsers.expat` en `xml.etree.ElementTree` gebruiken onvoldoende entropie voor Expat hash-flooding-bescherming, waardoor een vervaardigd XML-document hash-flooding kan activeren.rnrnVolledig mitigeren van deze kwetsbaarheid vereist zowel het bijwerken van libexpat naar 2.8.0 of hoger als het toepassen van deze patch.
Origineel (Engels) tonen
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.rnrnFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.