CVE-2026-7210

Source
https://cve.org/CVERecord?id=CVE-2026-7210
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-7210.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-7210
Aliases
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CGA (10)
DEBIAN (1)
ECHO (1)
MINI (5)
OESA (5)
openSUSE (6)
RHSA (5)
ROOT (4)
SUSE (12)
UBUNTU (1)
Related
Published
2026-05-11T17:19:09Z
Modified
2026-10-02T11:46:06Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
Details

xml.parsers.expat and xml.etree.ElementTree use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Database specific
{
    "cna_assigner": "PSF",
    "cwe_ids": [
        "CWE-331"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7210.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "3.10.22"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/python/cpython

Affected ranges

Type
GIT
Repo
https://github.com/python/cpython
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.11.0"
        },
        {
            "fixed": "3.11.16"
        },
        {
            "introduced": "3.12.0"
        },
        {
            "fixed": "3.12.14"
        },
        {
            "introduced": "3.13.0"
        },
        {
            "fixed": "3.13.14"
        },
        {
            "introduced": "3.14.0"
        },
        {
            "fixed": "3.14.6"
        },
        {
            "introduced": "3.15.0a1"
        },
        {
            "fixed": "3.15.0b2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v3.*
v3.12.0
v3.12.1
v3.12.10
v3.12.11
v3.12.12
v3.12.13
v3.12.2
v3.12.3
v3.12.4
v3.12.5
v3.12.6
v3.12.7
v3.12.8
v3.12.9
v3.13.0
v3.13.1
v3.13.10
v3.13.11
v3.13.12
v3.13.13
v3.13.2
v3.13.3
v3.13.4
v3.13.5
v3.13.6
v3.13.7
v3.13.8
v3.14.0
v3.14.1
v3.14.2
v3.14.3
v3.14.4
v3.14.5
v3.14.5rc1
v3.15.0b1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-7210.json"