Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2026-7210

HIGH · 7.5 CVSS Gepubliceerd: CWE-331

Beschrijving NL

`xml.parsers.expat` en `xml.etree.ElementTree` gebruiken onvoldoende entropie voor Expat hash-flooding-bescherming, waardoor een vervaardigd XML-document hash-flooding kan activeren.rnrnVolledig mitigeren van deze kwetsbaarheid vereist zowel het bijwerken van libexpat naar 2.8.0 of hoger als het toepassen van deze patch.

Origineel (Engels) tonen

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.rnrnFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Vendors

Python

Affected products

Python

References